cbcvebase.
CVE-2019-20795
published 2020-05-09

CVE-2019-20795: iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that…

PriorityP415medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.40%
33.1th percentile
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.

Affected

7 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianiproute2< iproute2 5.2.0-1 (bookworm)iproute2 5.2.0-1 (bookworm)
iproute2_projectiproute2< 5.1.05.1.0
iproute2_projectiproute2>= 0 < 5.2.0-15.2.0-1
iproute2_projectiproute2>= 0 < 5.2.0-15.2.0-1
iproute2_projectiproute2>= 0 < 5.2.0-15.2.0-1
iproute2_projectiproute2>= 0 < 5.2.0-15.2.0-1

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.