ZeroHour

CVE-2019-11815

PoC ×2
CVSS 3.1
8.1 high
EPSS
4%p91
Published
()
Modified
Description

An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.

Vendors
linuxcanonicaldebianopensusenetapp
Products
linux kernel, ubuntu linux, debian linux, leap, active iq unified manager, hci management node, snapprotect, solidfire, storage replication adapter, vasa provider for clustered data ontap, virtual storage console, hci compute node
Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news