cbcvebase.
CVE-2019-3896
published 2019-06-19

CVE-2019-3896: A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.2.41-1 (bookworm)linux 3.2.41-1 (bookworm)
linuxlinux_kernel>= 0 < 3.2.41-13.2.41-1
linuxlinux_kernel>= 0 < 3.2.41-13.2.41-1
linuxlinux_kernel>= 0 < 3.2.41-13.2.41-1
linuxlinux_kernel>= 0 < 3.2.41-13.2.41-1
linuxlinux_kernel2.6.0 – 2.6.39.4
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_workstation
the_linux_foundationkernel

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH