CVE-2019-15666Out-of-bounds Read in Kernel

Severity
4.4MEDIUMNVD
EPSS
5.2%
top 10.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateMay 24

Description

An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel< 5.0.19
Debianlinux/linux_kernel< 5.2.6-1+3
debiandebian/linux< linux 5.2.6-1 (bookworm)
NVDopensuse/leap15.0, 15.1+1

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v95m-j7gp-qgr2: An issue was discovered in the Linux kernel before 52022-05-24
OSV
CVE-2019-15666: An issue was discovered in the Linux kernel before 52019-08-27

📋Vendor Advisories

2
Red Hat
kernel: out-of-bounds array access in __xfrm_policy_unlink2019-08-27
Debian
CVE-2019-15666: linux - An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bo...2019

💬Community

2
Bugzilla
CVE-2019-15666 kernel: out-of-bounds array access in __xfrm_policy_unlink2019-08-30
Bugzilla
CVE-2019-15666 kernel: out-of-bounds array access in __xfrm_policy_unlink [fedora-all]2019-08-30