CVE-2019-17055: Low severity Linux Linux kernel vulnerability
A vulnerability was found in basesockcreate in drivers/isdn/mISDN/socket.c in the AFISDN network module in the Linux kernel does not enforce CAPNETRAW, which means that unprivileged users can create a raw socket.
Reference:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b91ee4aa2a2199ba4d4650706c272985a5a32d80
Other sources
A vulnerability was found in the Linux kernel’s implementation of the AFISDN protocol, which does not enforce the CAPNETRAW capability. This flaw can allow unprivileged users to create a raw socket for this protocol. This could further allow the user to control the availability of an existing ISDN circuit.
basesockcreate in drivers/isdn/mISDN/socket.c in the AFISDN network module in the Linux kernel through 5.3.2 does not enforce CAPNETRAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-754.28.1.el6 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.rt56.1131.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.rt13.51.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.3.2Patch CID-b91ee4aa2a21 - Compensating control
Blacklist the affected Linux kernel module to prevent it from loading: disable the mISDN_core.ko module (per Red Hat solution 41278 instructions).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-17055?
CVE-2019-17055 is classified as a medium severity vulnerability due to its potential exploitation by unprivileged users.
How do I fix CVE-2019-17055?
To fix CVE-2019-17055, upgrade to the recommended kernel versions provided by your Linux distribution, such as Red Hat or Debian.
Which systems are affected by CVE-2019-17055?
CVE-2019-17055 affects Linux kernel versions up to 5.3.2 and various distributions, including Red Hat, Debian, and Ubuntu.
Is CVE-2019-17055 exploitable remotely?
CVE-2019-17055 is not considered remotely exploitable as it requires local access to the system.
What is the impact of CVE-2019-17055?
The impact of CVE-2019-17055 allows unprivileged users to create raw sockets, which could facilitate further attacks on the system.