First published: Fri Nov 29 2019(Updated: )
illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Omniosce Omnios | <r151030 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19396 is a vulnerability in illumos as used in OmniOS Community Edition before r151030y that allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket.
CVE-2019-19396 has a severity rating of 7.5 (high).
The affected software for CVE-2019-19396 is Omniosce Omnios with versions up to and excluding r151030.
To fix CVE-2019-19396, it is recommended to update to OmniOS Community Edition r151030y or later.
You can find more information about CVE-2019-19396 at the following references: [link1](https://omniosce.org/article/030y-028ay-022dw.html) and [link2](https://www.illumos.org/issues/11556).