In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnection and re-connection, a local attacker can trigger multiple use-after-free conditions. This can result in a kernel crash, or potentially in privilege escalation. NOTE: this affects (for example) Linux distributions that use 4.9.x longterm kernels before 4.9.190 or 4.14.x longterm kernels before 4.14.139.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kpatch-patch-3_10_0-1062_4_3Upgrade kpatch-patch-3_10_0-1062_1_2-debuginfoUpgrade kpatch-patch-3_10_0-1062_1_1Upgrade kpatch-patch-3_10_0-1062_1_2Upgrade kpatch-patch-3_10_0-1062_4_1-debuginfoUpgrade kpatch-patch-3_10_0-1062-debuginfoUpgrade kernelUpgrade kpatch-patch-3_10_0-1062_1_1-debuginfoUpgrade kpatch-patch-3_10_0-1062_4_2Upgrade kpatch-patch-3_10_0-1062Upgrade kernel-rtUpgrade kpatch-patch-3_10_0-1062_4_1 | Nov 27, 2019 | Aug 20, 2019 |
| Debian | — | Upgrade linux | Aug 21, 2019 | Aug 21, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-perfUpgrade kernel-toolsUpgrade kernel-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-tools-libsUpgrade kernel-headersUpgrade kernelUpgrade perfUpgrade kernel-devel | Nov 19, 2019 | Aug 20, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade kernel-develUpgrade kernel-toolsUpgrade kernel-tools-libsUpgrade perfUpgrade kernel-headersUpgrade python-perfUpgrade kernel | Nov 19, 2019 | Aug 20, 2019 |
| Oracle_linux | — | Upgrade kernelUpgrade kernel-uek | Oct 3, 2019 | Aug 20, 2019 |
| Redhat_linux | — | Upgrade kpatch-patch-3_10_0-1062-debuginfoUpgrade kernel-rtUpgrade kpatch-patch-3_10_0-1062_1_2Upgrade kpatch-patch-3_10_0-1062_4_2Upgrade kpatch-patch-3_10_0-1062_4_1-debuginfoUpgrade kpatch-patch-3_10_0-1062Upgrade kpatch-patch-3_10_0-1062_1_2-debuginfoUpgrade kpatch-patch-3_10_0-1062_1_1-debuginfoUpgrade kpatch-patch-3_10_0-1062_1_1Upgrade kpatch-patch-3_10_0-1062_4_3Upgrade kernelUpgrade kpatch-patch-3_10_0-1062_4_1 | Nov 27, 2019 | Aug 20, 2019 |
| Suse | — | Upgrade kernel-defaultUpgrade kernel-obs-buildUpgrade kernel-docsUpgrade kernel-devel-azureUpgrade kernel-azure-baseUpgrade kernel-default-manUpgrade kernel-default-extraUpgrade kernel-source-azure | Sep 21, 2019 | Aug 20, 2019 |
| Ubuntu | — | Upgrade linux-kvmUpgrade linux-raspi2Upgrade linux-fipsUpgrade linux-snapdragonUpgrade linuxUpgrade linux-awsUpgrade linux-lts-xenial | Nov 19, 2024 | Aug 20, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 20, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub