CVE-2019-9003: Use After Free
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmimsghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-9003.
What is the description of the vulnerability?
The vulnerability is a use-after-free and OOPS vulnerability in the Linux kernel before 4.20.5, which can be triggered by certain simultaneous execution of code.
Which software is affected by this vulnerability?
The vulnerability affects the Linux kernel versions before 4.20.5.
How can this vulnerability be exploited?
The vulnerability can be exploited by arranging for certain simultaneous execution of the code.
Is there a fix available for this vulnerability?
Yes, the vulnerability can be fixed by updating the Linux kernel to version 4.20.5 or later.