In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnection and re-connection, a local attacker can trigger multiple use-after-free conditions. This can result in a kernel crash, or potentially in privilege escalation. NOTE: this affects (for example) Linux distributions that use 4.9.x longterm kernels before 4.9.190 or 4.14.x longterm kernels before 4.14.139.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kpatch-patch-3_10_0-1062_4_1Upgrade kernel-rtUpgrade kpatch-patch-3_10_0-1062_1_2-debuginfoUpgrade kpatch-patch-3_10_0-1062_4_2Upgrade kpatch-patch-3_10_0-1062Upgrade kernelUpgrade kpatch-patch-3_10_0-1062_1_2Upgrade kpatch-patch-3_10_0-1062-debuginfoUpgrade kpatch-patch-3_10_0-1062_1_1Upgrade kpatch-patch-3_10_0-1062_4_3Upgrade kpatch-patch-3_10_0-1062_1_1-debuginfoUpgrade kpatch-patch-3_10_0-1062_4_1-debuginfo | Nov 27, 2019 | Aug 20, 2019 |
| Debian | — | Upgrade linux | Aug 21, 2019 | Aug 21, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade kernelUpgrade kernel-develUpgrade perfUpgrade kernel-tools-libsUpgrade python-perfUpgrade kernel-debuginfoUpgrade kernel-toolsUpgrade kernel-headersUpgrade kernel-debuginfo-common-x86_64 | Nov 19, 2019 | Aug 20, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade perfUpgrade kernel-tools-libsUpgrade kernel-toolsUpgrade kernel-develUpgrade python-perfUpgrade kernel-headersUpgrade kernel | Nov 19, 2019 | Aug 20, 2019 |
| Oracle_linux | — | Upgrade kernelUpgrade kernel-uek | Oct 3, 2019 | Aug 20, 2019 |
| Redhat_linux | — | Upgrade kpatch-patch-3_10_0-1062_1_1Upgrade kpatch-patch-3_10_0-1062_4_2Upgrade kpatch-patch-3_10_0-1062_4_1Upgrade kpatch-patch-3_10_0-1062_4_1-debuginfoUpgrade kpatch-patch-3_10_0-1062_4_3Upgrade kpatch-patch-3_10_0-1062Upgrade kpatch-patch-3_10_0-1062_1_2-debuginfoUpgrade kpatch-patch-3_10_0-1062_1_1-debuginfoUpgrade kernelUpgrade kpatch-patch-3_10_0-1062_1_2Upgrade kernel-rtUpgrade kpatch-patch-3_10_0-1062-debuginfo | Nov 27, 2019 | Aug 20, 2019 |
| Suse | — | Upgrade kernel-docsUpgrade kernel-defaultUpgrade kernel-obs-buildUpgrade kernel-azure-baseUpgrade kernel-devel-azureUpgrade kernel-default-manUpgrade kernel-default-extraUpgrade kernel-source-azure | Sep 21, 2019 | Aug 20, 2019 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-snapdragonUpgrade linuxUpgrade linux-lts-xenialUpgrade linux-fipsUpgrade linux-kvmUpgrade linux-raspi2 | Nov 19, 2024 | Aug 20, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 20, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub