ALPINE-CVE-2019-20795 PUBLISHED CVSS 4.400000095367432 MEDIUM

iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.

Risk Scores

CVSS v3.1
4.400000095367432
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.21iproute22.6.38-r1, 3.10.0-r0, 2.6.31-r1
Alpine:v3.11iproute20, 2.6.28-r0, 2.6.29.1-r0
Alpine:v3.9iproute23.14.0-r0, 3.10.0-r0, 4.7.0-r0
Alpine:v3.23iproute22.6.29.1-r0, 3.10.0-r0, 2.6.38-r0
Alpine:v3.18iproute23.12.0-r0, 4.20.0-r0, 4.7.0-r0
Alpine:v3.15iproute23.10.0-r0, 0, 2.6.28-r0
Alpine:v3.16iproute22.6.38-r0, 3.15.0-r0, 3.18.0-r0
Alpine:v3.22iproute23.9.0-r0, 2.6.35-r0, 4.12.0-r0
Alpine:v3.14iproute24.10.0-r0, 3.6.0-r0, 2.6.31-r1
Alpine:v3.13iproute22.6.31-r1, 0, 2.6.28-r0
Alpine:v3.20iproute22.6.38-r0, 4.4.0-r0, 4.4.0-r0
Alpine:v3.10iproute22.6.35-r3, 4.19.0-r0, 4.2.0-r0
Alpine:v3.12iproute22.6.31-r0, 2.6.28-r0, 2.6.31-r1
Alpine:v3.17iproute24.6.0-r1, 4.12.0-r0, 4.2.0-r0
Alpine:v3.19iproute23.3.0-r0, 0, 2.6.28-r0

Timeline

References

Open in Interactive Console →