CVE-2023-2019
published 2023-04-24CVE-2023-2019: A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference…
PriorityP415medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.34%
26.7th percentile
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.19.6-1 (bookworm) | linux 5.19.6-1 (bookworm) |
| linux | linux_kernel | < 6.0 | 6.0 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| msrc | cbl2_kernel_5.15.111.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.4MEDIUM
cisa7.8HIGH
vendor_oracle8.8CRITICAL
vendor_debian4.4MEDIUM
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Oracle
Oracle Oracle Health Sciences Applications Risk Matrix: Core (Telerik UI for ASP.NET AJAX) — CVE-2019-18935
vendor_oracle·2023-04-15·CVSS 8.8
CVE-2019-18935 [CRITICAL] Oracle Oracle Health Sciences Applications Risk Matrix: Core (Telerik UI for ASP.NET AJAX) — CVE-2019-18935
Oracle Oracle Health Sciences Applications Risk Matrix: Core (Telerik UI for ASP.NET AJAX) vulnerability
CVE: CVE-2019-18935
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
kernel: netdevsim: fib: reference count leak on route deletion failure
vendor_redhat·2023-04-13·CVSS 4.4
CVE-2023-2019 [MEDIUM] CWE-911 kernel: netdevsim: fib: reference count leak on route deletion failure
kernel: netdevsim: fib: reference count leak on route deletion failure
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
A flaw was found in the Linux kernel's netdevsim device driver within the scheduling of events. This issue results from improper management of a reference count. This flaw allows an attacker to create a denial of service condition on the system.
Statement: Red Hat Enterprise Linux 6 and 7 are not affected by this flaw as they did not ship the `netdevsim` device driver. Red Hat Enterprise Linux 8 is not affected as it did not include the upstream commit that introduced this
Microsoft
A flaw was found in the Linux kernel's netdevsim device driver within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to crea
vendor_msrc·2023-04-11·CVSS 4.4
CVE-2023-2019 [MEDIUM] CWE-911 A flaw was found in the Linux kernel's netdevsim device driver within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to crea
A flaw was found in the Linux kernel's netdevsim device driver within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additi
CISA
Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
cisa·2023-04-07·CVSS 7.8
CVE-2019-1388 [HIGH] CWE-269 Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
Required Action: Apply updates per vendor instructions.
Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1388; https://nvd.nist.gov/vuln/detail/CVE-2019-1388
Remediation Due Date: 2023-04-28
Debian
CVE-2023-2019: linux - A flaw was found in the Linux kernel's netdevsim device driver, within the sched...
vendor_debian·2023·CVSS 4.4
CVE-2023-2019 [MEDIUM] CVE-2023-2019: linux - A flaw was found in the Linux kernel's netdevsim device driver, within the sched...
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
Scope: local
bookworm: resolved (fixed in 5.19.6-1)
bullseye: resolved
forky: resolved (fixed in 5.19.6-1)
sid: resolved (fixed in 5.19.6-1)
trixie: resolved (fixed in 5.19.6-1)
OSV
CVE-2023-2019: A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events
osv·2023-04-24·CVSS 4.4
CVE-2023-2019 [MEDIUM] CVE-2023-2019: A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
GHSA
GHSA-9vmw-8f7f-qhch: A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events
ghsa_unreviewed·2023-04-24
CVE-2023-2019 [MEDIUM] CWE-911 GHSA-9vmw-8f7f-qhch: A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-2019 kernel: netdevsim: fib: reference count leak on route deletion failure
bugzilla·2023-04-24·CVSS 4.4
CVE-2023-2019 [MEDIUM] CVE-2023-2019 kernel: netdevsim: fib: reference count leak on route deletion failure
CVE-2023-2019 kernel: netdevsim: fib: reference count leak on route deletion failure
A reference count issue was found in the Linux kernel's netdevsim device driver. Quoting ZDI security advisory [1]:
"This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the scheduling of events. The issue results from the improper management of a reference count. An attacker can leverage this vulnerability to create a denial-of-service condition on the system."
[1] https://www.zerodayinitiative.com/advisories/ZDI-CAN-17811/
Discussion:
Upstream fix:
https://github.
Checkpoint
31st October – Threat Intelligence Report
blogs_checkpoint·2022-10-31
CVE-2022-3723 31st October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 31st October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st October, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
US-based communications company Twilio has disclosed a new data breach that occurred on June 2022 allegedly by the same threat actors behind the August hack. The hackers have used voice phishing to trick a Twilio employee into handling over their credentials, which the hackers then used to access customer information.
Cu
Checkpoint
10th October – Threat Intelligence Report
blogs_checkpoint·2022-10-10
CVE-2022-41352 10th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th October, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
CommonSpirit Health, the second-largest nonprofit hospital chain in the U.S with 140 hospitals and over 1,000 facilities in 21 states, suffered a cybersecurity incident that disrupted medical services across the country. Facilities in Iowa, Nebraska, Tennessee and Washington were among those affected. The nature of the at
Checkpoint
28th June – Threat Intelligence Report
blogs_checkpoint·2021-06-28
CVE-2021-21998 28th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Russian-based threat group Nobelium is using password spraying and brute force attacks to gain access to corporate networks. The group, which was behind the SolarWinds supply-chain attack, deployed an information-stealing Trojan on a Microsoft customer support agent’s computer to steal information. Over half of the targets were
Crowdstrike
CrowdStrike Named a Leader with “Exceptional” MDR Service: 2023 Forrester Wave for MDR
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] CrowdStrike Named a Leader with “Exceptional” MDR Service: 2023 Forrester Wave for MDR
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
https://bugzilla.redhat.com/show_bug.cgi?id=2189137https://github.com/torvalds/linux/commit/180a6a3ee60ahttps://www.zerodayinitiative.com/advisories/ZDI-CAN-17811/https://bugzilla.redhat.com/show_bug.cgi?id=2189137https://github.com/torvalds/linux/commit/180a6a3ee60ahttps://www.zerodayinitiative.com/advisories/ZDI-CAN-17811/
2023-04-24
Published