First published: Tue Oct 01 2019(Updated: )
ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | >=3.16<=5.3.2 | |
Debian | =8.0 | |
Fedora | =29 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Linux Kernel | >=3.16<=5.3.2 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17052 is considered a medium severity vulnerability due to the potential for unprivileged users to create raw sockets.
To fix CVE-2019-17052, update your Linux kernel to version 5.10.223-1, 5.10.226-1 or later.
CVE-2019-17052 affects Linux kernel versions from 3.16 up to 5.3.2.
CVE-2019-17052 allows unprivileged users to create raw sockets, potentially leading to network abuse or system compromise.
CVE-2019-17052 impacts multiple distributions, including Debian 8.0, Fedora 29, and several versions of Ubuntu.