CVE-2019-9003Use After Free in Kernel

CWE-416Use After Free10 documents7 sources
Severity
7.5HIGHNVD
OSV7.8
EPSS
6.8%
top 8.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 13

Description

In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.184.19.18+2
Debianlinux/linux_kernel< 4.19.20-1+3
debiandebian/linux< linux 4.19.20-1 (bookworm)
NVDopensuse/leap15.0

Also affects: Ubuntu Linux 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9pwg-j47x-j9gj: In the Linux kernel before 42022-05-13
OSV
linux-hwe, linux-azure vulnerabilities2019-04-02
OSV
CVE-2019-9003: In the Linux kernel before 42019-02-22

📋Vendor Advisories

4
Ubuntu
Linux kernel (HWE) vulnerabilities2019-04-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Red Hat
kernel: use-after-free and OOPS in drivers/char/ipmi/ipmi_msghandler.c2019-01-16
Debian
CVE-2019-9003: linux - In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipm...2019

💬Community

2
Bugzilla
CVE-2019-9003 kernel: use-after-free and OOPS in drivers/char/ipmi/ipmi_msghandler.c [fedora-all]2019-02-25
Bugzilla
CVE-2019-9003 kernel: use-after-free and OOPS in drivers/char/ipmi/ipmi_msghandler.c2019-02-25