CVE-2019-18903: wicked: Use-after-free when receiving invalid DHCP6 IA_PD option
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.9.1. openSUSE Factory wicked versions prior to 0.6.62.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18903?
CVE-2019-18903 is a Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, openSUSE Leap 15.1, and Factory that allows remote attackers to cause DoS or potentially code execution.
Which software versions are affected by CVE-2019-18903?
SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1 are affected by CVE-2019-18903.
How severe is CVE-2019-18903?
CVE-2019-18903 has a severity rating of 9.8 (critical).
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for CVE-2019-18903 is 416.
How do I fix CVE-2019-18903?
To fix CVE-2019-18903, upgrade to wicked version 0.6.60-2.18.1 or later.