CVE-2019-18902: wicked: Use-after-free when receiving invalid DHCP6 client options
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.6.1. openSUSE Factory wicked versions prior to 0.6.62.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18902?
CVE-2019-18902 is a Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory that allows remote attackers to cause DoS or potentially code execution.
Which software versions are affected by CVE-2019-18902?
The affected software versions are SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1, SUSE Linux Enterprise Server 15, openSUSE Leap 15.1, and Factory.
What is the severity of CVE-2019-18902?
CVE-2019-18902 has a severity rating of critical with a CVSS score of 9.8.
How can CVE-2019-18902 be exploited?
CVE-2019-18902 can be exploited by remote attackers to cause DoS or potentially execute code.
Is there a fix available for CVE-2019-18902?
Yes, a fix for CVE-2019-18902 is available. It is recommended to update to wicked version 0.6.60-3.5.1 or later for SUSE Linux Enterprise Server 12.