CVE-2019-3896 PUBLISHED

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).

EPSS 0.07% · 20.5th percentile

Risk Scores

EPSS Score
0.07%
20.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlinux-lts-xenial0, 4.4.0-130.156~14.04.1, 4.4.0-128.154~14.04.1
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1186.201~14.04.1, 4.15.0-1171.186~14.04.1, 0
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1139.145, 0, 4.4.0-1002.2
Ubuntu:Pro:14.04:LTSlinux0, 3.13.0-211.262, 3.13.0-210.261

Timeline

References

Open in Interactive Console →