CVE-2019-15239: Use After Free

Published Aug 20, 2019
·
Updated

A flaw was found in the way the Linux kernel's networking subsystem handled the write queue between TCP disconnection and re-connections. A local attacker could use this flaw to trigger multiple use-after-free conditions potentially escalating their privileges on the system.

Other sources

A vulnerability was found in In the Linux kernel, a certain net/ipv4/tcpoutput.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnection and re-connection, a local attacker can trigger multiple use-after-free conditions. This can result in a kernel crash, or potentially in privilege escalation.

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7f582b248d0a86bae5788c548d7bb5bca6f7691a https://lore.kernel.org/stable/41a61a2f87691d2bc839f26cdfe6f5ff2f51e472.camel@decadent.org.uk/

Red Hat

In the Linux kernel, a certain net/ipv4/tcpoutput.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnection and re-connection, a local attacker can trigger multiple use-after-free conditions. This can result in a kernel crash, or potentially in privilege escalation. NOTE: this affects (for example) Linux distributions that use 4.9.x longterm kernels before 4.9.190 or 4.14.x longterm kernels before 4.14.139.

Affected Software

7 affected componentsFixes available
redhat/kernel-rt<0:3.10.0-1062.7.1.rt56.1030.el7
0:3.10.0-1062.7.1.rt56.1030.el7
redhat/kernel<0:3.10.0-1062.7.1.el7
0:3.10.0-1062.7.1.el7
debian/linux
4.19.249-24.19.289-25.10.197-15.10.191-16.1.66-16.1.52-16.5.13-16.6.8-1
Google Android
Linux Linux Kernel=4.16.12
Debian Linux=9.0
Debian Linux=10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/kernel-rt to a version that resolves this vulnerability.

    Fixed in 0:3.10.0-1062.7.1.rt56.1030.el7
  2. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:3.10.0-1062.7.1.el7
  3. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 4.19.249-2Fixed in 4.19.289-2Fixed in 5.10.197-1Fixed in 5.10.191-1Fixed in 6.1.66-1Fixed in 6.1.52-1Fixed in 6.5.13-1Fixed in 6.6.8-1
  4. Upgrade

    Upgrade Linux kernel (net/ipv4/tcp_output.c) to a version that resolves this vulnerability.

    Fixed in 4.9.190
  5. Upgrade

    Upgrade Linux kernel (net/ipv4/tcp_output.c) to a version that resolves this vulnerability.

    Fixed in 4.14.139
  6. Upgrade

    Upgrade Linux kernel (net/ipv4/tcp_output.c) to a version that resolves this vulnerability.

    Fixed in 4.16.12

Event History

Aug 20, 2019
CVE Published
12:00 AM
CVE Published
via MITRE·07:25 AM
Data Sourced
via MITRE·07:25 AM
Description
Aug 30, 2019
Data Sourced
via Red Hat·07:59 AM
DescriptionSeverityAffected Software
Dec 2, 2019
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2019-15239?

CVE-2019-15239 is a vulnerability found in the Linux kernel's networking subsystem that can be exploited to cause a denial of service or potentially execute arbitrary code.

2

How severe is CVE-2019-15239?

CVE-2019-15239 has a severity rating of 7.4 out of 10, indicating a high severity.

3

Which versions of Linux kernel are affected by CVE-2019-15239?

CVE-2019-15239 affects Linux kernel versions 4.16.12, 3.10.0-1062.7.1.rt56.1030.el7, and 3.10.0-1062.7.1.el7.

4

How can CVE-2019-15239 be exploited?

CVE-2019-15239 can be exploited by an attacker to manipulate the write queue and potentially execute arbitrary code or cause a denial of service.

5

Is there a fix for CVE-2019-15239?

Yes, a fix for CVE-2019-15239 is available. It is recommended to update the affected Linux kernel versions to the patched versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203