CVE-2019-16714

Severity
7.5HIGH
EPSS
1.1%
top 21.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateMay 24

Description

In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel< 5.2.14
Debianlinux< 5.2.17-1+3

Also affects: Ubuntu Linux 18.04, 19.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pv85-r7p2-8r62: In the Linux kernel before 52022-05-24
CVEList
CVE-2019-16714: In the Linux kernel before 52019-09-23
OSV
CVE-2019-16714: In the Linux kernel before 52019-09-23

📋Vendor Advisories

4
Ubuntu
Linux kernel (HWE) vulnerabilities2019-10-22
Ubuntu
Linux kernel vulnerabilities2019-10-17
Red Hat
kernel: vulnerability in rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information2019-09-23
Debian
CVE-2019-16714: linux - In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows a...2019

💬Community

4
Bugzilla
CVE-2019-16714 kernel: vulnerability in rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information [fedora-all]2019-09-27
Bugzilla
CVE-2019-16714 kernel: vulnerability in rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information [fedora-all]2019-09-25
Bugzilla
CVE-2019-16714 kernel: vulnerability in rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information2019-09-25
Bugzilla
CVE-2019-16714 kernel: vulnerability in rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information [fedora-all]2019-09-25