CVE-2019-18198
published 2019-10-18CVE-2019-18198: In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.46%
37.3th percentile
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | — | — |
| linux | linux_kernel | >= 5.3 < 5.3.4 | 5.3.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2019-10-21
CVE-2019-18198 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
It was discovered that the IPv6 routing implementation in the Linux kernel
contained a reference counting error leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEA
Red Hat
kernel: memory leak in fib6_rule_suppress could result in DoS
vendor_redhat·2019-10-03·CVSS 7.8
CVE-2021-3892 [HIGH] CWE-401 kernel: memory leak in fib6_rule_suppress could result in DoS
kernel: memory leak in fib6_rule_suppress could result in DoS
A memory leak flaw was reported in firewalld when IPv6_rpfilter is enabled and a suppress_prefix rule is present in the IPv6 routing rules. In such scenarios, every incoming packet will leak an allocation in ip6_dst_cache slab cache.
Statement: This flaw was found to be a duplicate of CVE-2019-18198. Please see https://access.redhat.com/security/cve/CVE-2019-18198 for information about affected products and security errata.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Red Hat
kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c
vendor_redhat·2019-09-24·CVSS 7.8
CVE-2019-18198 [HIGH] CWE-772 kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c
kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
A flaw was found in the Linux kernel’s IPv6 routing system. A local attacker with the ability to configure routing can create a situation where they can corrupt memory or possibly escalate privileges.
Statement: This flaw is rated as moderate as setting up the condition requires CAP_NET_ADMIN privileges which are not available to regular users.
Mitigation: As the IPV6 module will be auto-loaded when required, its use can b
Debian
CVE-2019-18198: linux - In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule...
vendor_debian·2019·CVSS 7.8
CVE-2019-18198 [HIGH] CVE-2019-18198: linux - In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule...
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-3wc6-3hc2-3wc8: In the Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2019-18198 [HIGH] CWE-772 GHSA-3wc6-3hc2-3wc8: In the Linux kernel before 5
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
OSV
CVE-2019-18198: In the Linux kernel before 5
osv·2019-10-17·CVSS 7.8
CVE-2019-18198 [HIGH] CVE-2019-18198: In the Linux kernel before 5
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18198 kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c [fedora-all]
bugzilla·2019-11-12·CVSS 7.8
CVE-2019-18198 [HIGH] CVE-2019-18198 kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c [fedora-all]
CVE-2019-18198 kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2019-18198 kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c
bugzilla·2019-11-12·CVSS 7.8
CVE-2019-18198 [HIGH] CVE-2019-18198 kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c
CVE-2019-18198 kernel: reference count usage error in fib6_rule_suppress function in net/ipv6/fib6_rules.c
A flaw was found in the Linux kernels IPV6 subsystem. Route reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c. A local attacker with the ability to trigger packets being sent over a specific route that implements suppress_prefixlength.
The suppress_prefixlength routes are not standard and require administrative access to insert.
Upstream commit:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ca7a03c4175366a92cee0ccc4fec0038c3266e26
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1771487]
---
This was fixed for Fedora with the 5.3.4 stable kerne
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.4https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ca7a03c4175366a92cee0ccc4fec0038c3266e26https://github.com/torvalds/linux/commit/ca7a03c4175366a92cee0ccc4fec0038c3266e26https://launchpad.net/bugs/1847478https://security.netapp.com/advisory/ntap-20191031-0005/https://usn.ubuntu.com/4161-1/https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.4https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ca7a03c4175366a92cee0ccc4fec0038c3266e26https://github.com/torvalds/linux/commit/ca7a03c4175366a92cee0ccc4fec0038c3266e26https://launchpad.net/bugs/1847478https://security.netapp.com/advisory/ntap-20191031-0005/https://usn.ubuntu.com/4161-1/
2019-10-18
Published