CVE-2019-17055: Low severity Linux Linux kernel vulnerability

Published Sep 20, 2019
·
Updated

A vulnerability was found in basesockcreate in drivers/isdn/mISDN/socket.c in the AFISDN network module in the Linux kernel does not enforce CAPNETRAW, which means that unprivileged users can create a raw socket.

Reference:

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b91ee4aa2a2199ba4d4650706c272985a5a32d80

Other sources

A vulnerability was found in the Linux kernel’s implementation of the AFISDN protocol, which does not enforce the CAPNETRAW capability. This flaw can allow unprivileged users to create a raw socket for this protocol. This could further allow the user to control the availability of an existing ISDN circuit.

basesockcreate in drivers/isdn/mISDN/socket.c in the AFISDN network module in the Linux kernel through 5.3.2 does not enforce CAPNETRAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.

Affected Software

18 affected componentsFixes available
redhat/kernel<0:2.6.32-754.28.1.el6
0:2.6.32-754.28.1.el6
redhat/kernel-rt<0:3.10.0-1160.rt56.1131.el7
0:3.10.0-1160.rt56.1131.el7
redhat/kernel<0:3.10.0-1160.el7
0:3.10.0-1160.el7
redhat/kernel-rt<0:4.18.0-193.rt13.51.el8
0:4.18.0-193.rt13.51.el8
redhat/kernel<0:4.18.0-193.el8
0:4.18.0-193.el8
Linux Linux kernel<=5.3.2
Debian Debian Linux=8.0
Fedoraproject Fedora=29
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
openSUSE Leap=15.0
openSUSE Leap=15.1
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
debian/linux
5.10.223-15.10.262-16.1.176-16.1.180-16.12.94-16.12.101-17.1.7-17.1.8-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:2.6.32-754.28.1.el6
  2. Upgrade

    Upgrade redhat/kernel-rt to a version that resolves this vulnerability.

    Fixed in 0:3.10.0-1160.rt56.1131.el7
  3. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:3.10.0-1160.el7
  4. Upgrade

    Upgrade redhat/kernel-rt to a version that resolves this vulnerability.

    Fixed in 0:4.18.0-193.rt13.51.el8
  5. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:4.18.0-193.el8
  6. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.3.2Patch CID-b91ee4aa2a21
  8. Compensating control

    Blacklist the affected Linux kernel module to prevent it from loading: disable the mISDN_core.ko module (per Red Hat solution 41278 instructions).

Event History

Sep 20, 2019
CVE Published
12:00 AM
Oct 1, 2019
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 3, 2019
Data Sourced
via Red Hat·04:49 PM
DescriptionSeverityAffected Software
Jun 22, 2026
Data Sourced
via Launchpad·09:53 AM
Description
Aug 12, 2026
Data Sourced
via Debian·10:33 AM
DescriptionAffected Software
Aug 15, 2026
Data Sourced
via Ubuntu·10:33 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-17055?

CVE-2019-17055 is classified as a medium severity vulnerability due to its potential exploitation by unprivileged users.

2

How do I fix CVE-2019-17055?

To fix CVE-2019-17055, upgrade to the recommended kernel versions provided by your Linux distribution, such as Red Hat or Debian.

3

Which systems are affected by CVE-2019-17055?

CVE-2019-17055 affects Linux kernel versions up to 5.3.2 and various distributions, including Red Hat, Debian, and Ubuntu.

4

Is CVE-2019-17055 exploitable remotely?

CVE-2019-17055 is not considered remotely exploitable as it requires local access to the system.

5

What is the impact of CVE-2019-17055?

The impact of CVE-2019-17055 allows unprivileged users to create raw sockets, which could facilitate further attacks on the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203