CVE-2019-9003
22.02.2019, 15:29
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 4.18 ≤ 𝑥 < 4.19.18 |
| linux | linux_kernel | 4.20 ≤ 𝑥 < 4.20.5 |
| linux | linux_kernel | 5.0:rc1 |
| linux | linux_kernel | 5.0:rc2 |
| linux | linux_kernel | 5.0:rc3 |
| linux | linux_kernel | 5.0:rc4 |
| netapp | hci_management_node | - |
| netapp | snapprotect | - |
| netapp | solidfire | - |
| netapp | cn1610_firmware | - |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| opensuse | leap | 15.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| linux |
| ||||||||
| linux-aws |
| ||||||||
| linux-aws-hwe |
| ||||||||
| linux-azure |
| ||||||||
| linux-azure-edge |
| ||||||||
| linux-euclid |
| ||||||||
| linux-flo |
| ||||||||
| linux-gcp |
| ||||||||
| linux-gcp-edge |
| ||||||||
| linux-gke |
| ||||||||
| linux-goldfish |
| ||||||||
| linux-grouper |
| ||||||||
| linux-hwe |
| ||||||||
| linux-hwe-edge |
| ||||||||
| linux-kvm |
| ||||||||
| linux-lts-trusty |
| ||||||||
| linux-lts-utopic |
| ||||||||
| linux-lts-vivid |
| ||||||||
| linux-lts-wily |
| ||||||||
| linux-lts-xenial |
| ||||||||
| linux-maguro |
| ||||||||
| linux-mako |
| ||||||||
| linux-manta |
| ||||||||
| linux-oem |
| ||||||||
| linux-oracle |
| ||||||||
| linux-raspi2 |
| ||||||||
| linux-snapdragon |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| kernel-azure |
| ||||||||||||||||
| kernel-azure-base |
| ||||||||||||||||
| kernel-default |
| ||||||||||||||||
| kernel-default-base |
| ||||||||||||||||
| kernel-default-man |
| ||||||||||||||||
| kernel-docs |
| ||||||||||||||||
| kernel-macros |
| ||||||||||||||||
| kernel-obs-build |
| ||||||||||||||||
| kernel-source |
| ||||||||||||||||
| kernel-source-azure |
| ||||||||||||||||
| kernel-syms |
| ||||||||||||||||
| kernel-syms-azure |
| ||||||||||||||||
| kernel-vanilla-base |
| ||||||||||||||||
| kernel-zfcpdump |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| bpftool |
| ||||
| kernel |
| ||||
| kernel-abi-whitelists |
| ||||
| kernel-core |
| ||||
| kernel-debug |
| ||||
| kernel-debug-core |
| ||||
| kernel-debug-devel |
| ||||
| kernel-debug-modules |
| ||||
| kernel-debug-modules-extra |
| ||||
| kernel-devel |
| ||||
| kernel-doc |
| ||||
| kernel-modules |
| ||||
| kernel-modules-extra |
| ||||
| kernel-tools |
| ||||
| kernel-tools-libs |
| ||||
| kernel-tools-libs-devel |
| ||||
| kernel-zfcpdump |
| ||||
| kernel-zfcpdump-core |
| ||||
| kernel-zfcpdump-devel |
| ||||
| kernel-zfcpdump-modules |
| ||||
| kernel-zfcpdump-modules-extra |
| ||||
| perf |
| ||||
| python3-perf |
|
Common Weakness Enumeration
References