ZeroHour

CVE-2019-9003

CVSS 3.1
7.5 high
EPSS
5%p92
Published
()
Modified
Description

In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.

Vendors
linuxnetappcanonicalopensuse
Products
linux kernel, hci management node, snapprotect, solidfire, cn1610 firmware, ubuntu linux, leap
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.