CVE-2019-8956: Use After Free
In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctpsendmsg()" function (net/sctp/socket.c) when handling SCTPSENDALL flag can be exploited to corrupt memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux Kernelto a version that resolves this vulnerability.Fixed in 4.20.8 - Upgrade
Upgrade
Linux Kernelto a version that resolves this vulnerability.Fixed in 4.19.21
Event History
Frequently Asked Questions
What is CVE-2019-8956?
CVE-2019-8956 is a vulnerability in the Linux Kernel that allows for a use-after-free error in the "sctp_sendmsg()" function when handling SCTP_SENDALL flag, which can be exploited to corrupt memory.
What is the severity of CVE-2019-8956?
The severity of CVE-2019-8956 is not provided.
How can I exploit CVE-2019-8956?
Details on how to exploit CVE-2019-8956 are not provided.
How do I fix CVE-2019-8956?
To fix CVE-2019-8956, update your Linux Kernel to versions 4.20.8 or 4.19.21.
Where can I find more information about CVE-2019-8956?
You can find more information about CVE-2019-8956 at the following references: [1] [2] [3]