CVE-2019-18198 PUBLISHED

In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.

EPSS 0.10% · 28.2th percentile

Risk Scores

EPSS Score
0.10%
28.2th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-gkeop5.4.0-1097.101, 0, 5.4.0-1008.9
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:22.04:LTSlinux-riscv5.13.0-1006.6+22.04.1, 5.13.0-1004.4, 0
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:20.04:LTSlinux-gkeop-5.155.15.0-1025.30~20.04.1, 5.15.0-1024.29~20.04.1, 5.15.0-1023.28~20.04.1
Ubuntu:20.04:LTSlinux-riscv5.4.0-39.44, 0, 5.4.0-24.28
Ubuntu:20.04:LTSlinux-gke5.4.0-1056.59, 5.4.0-1090.97, 5.4.0-1087.94
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1065.68+cvm2.1, 5.4.0-1063.66+cvm3.2, 5.4.0-1063.66+cvm2.2
Ubuntu:20.04:LTSlinux-raspi25.3.0-1015.17, 5.3.0-1017.19, 5.3.0-1007.8
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0

Timeline

References

Open in Interactive Console →