First published: Wed May 08 2019(Updated: )
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | <=4.9.168-2<=4.19.28-2<=3.16.64-2<=4.9.168-1 | 4.19.37-1 4.9.168-1+deb9u3 |
Linux Kernel | >=4.3<4.4.179 | |
Linux Kernel | >=4.9<4.9.169 | |
Linux Kernel | >=4.14<4.14.112 | |
Linux Kernel | >=4.19<4.19.35 | |
Linux Kernel | >=5.0<5.0.8 | |
Linux Kernel | =5.1-rc1 | |
Linux Kernel | =5.1-rc2 | |
Linux Kernel | =5.1-rc3 | |
Linux Kernel | =5.1-rc4 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
openSUSE | =42.3 | |
NetApp Active IQ Unified Manager for VMware vSphere | >=9.5 | |
netapp hci management node | ||
NetApp SnapProtect | ||
netapp solidfire | ||
NetApp Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere | =7.2 | |
NetApp VASA Provider | >=7.2 | |
NetApp Virtual Storage Console for VMware vSphere | >=7.2 | |
netapp hci compute node | ||
netapp hci storage node | ||
All of | ||
NetApp CN1610 | ||
NetApp CN1610 Firmware | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.13-1 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Debian | =8.0 | |
Debian | =9.0 | |
NetApp CN1610 | ||
NetApp CN1610 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11815 is classified as a high severity vulnerability due to the potential for a use-after-free condition.
To fix CVE-2019-11815, update the Linux kernel to versions 5.0.8 or later, or the specific patched versions provided by your distribution.
CVE-2019-11815 is a vulnerability characterized as a race condition leading to a use-after-free in the Linux kernel.
CVE-2019-11815 affects various versions of the Linux kernel before 5.0.8 and specific distributions such as Debian and Ubuntu.
An attacker could exploit CVE-2019-11815 to execute arbitrary code or cause a denial of service due to the race condition in net namespace cleanup.