In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 18, 2019 |
| Suse | — | Upgrade kernel-default | Feb 4, 2022 | Oct 18, 2019 |
| Ubuntu | — | Upgrade linux-image-lowlatencyUpgrade linux-image-gcpUpgrade linux-image-5.3.0-19-generic-lpaeUpgrade linux-image-generic-lpaeUpgrade linux-image-raspi2Upgrade linux-image-azureUpgrade linux-image-5.3.0-1004-kvmUpgrade linux-image-awsUpgrade linux-image-kvmUpgrade linux-image-5.3.0-19-lowlatencyUpgrade linux-image-5.3.0-1005-gcpUpgrade linux-image-gkeUpgrade linux-image-5.3.0-19-snapdragonUpgrade linux-image-virtualUpgrade linux-image-snapdragonUpgrade linux-image-genericUpgrade linux-image-5.3.0-1008-raspi2Upgrade linux-image-5.3.0-19-genericUpgrade linux-image-5.3.0-1004-azureUpgrade linux-image-5.3.0-1004-aws | Oct 22, 2019 | Oct 18, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub