cbcvebase.
CVE-2019-17055
published 2019-10-01

CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that…

PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
0.54%
42.5th percentile
base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.

Affected

21 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.3.7-1 (bookworm)linux 5.3.7-1 (bookworm)
fedoraprojectfedora
linuxlinux_kernel<= 5.3.2
linuxlinux_kernel>= 0 < 5.3.7-15.3.7-1
linuxlinux_kernel>= 0 < 5.3.7-15.3.7-1
linuxlinux_kernel>= 0 < 5.3.7-15.3.7-1
linuxlinux_kernel>= 0 < 5.3.7-15.3.7-1
linuxlinux_kernel>= 0 < 4.4.0-168.1974.4.0-168.197
linuxlinux_kernel>= 0 < 4.4.0-169.1984.4.0-169.198
linuxlinux_kernel>= 0 < 4.15.0-70.794.15.0-70.79
linuxlinux_kernel>= 0 < 4.15.0-69.784.15.0-69.78
opensuseleap
opensuseleap
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.