In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 18, 2019 |
| Suse | — | Upgrade kernel-default | Feb 4, 2022 | Oct 18, 2019 |
| Ubuntu | — | Upgrade linux-image-snapdragonUpgrade linux-image-5.3.0-19-genericUpgrade linux-image-5.3.0-1005-gcpUpgrade linux-image-5.3.0-1004-awsUpgrade linux-image-genericUpgrade linux-image-5.3.0-1008-raspi2Upgrade linux-image-virtualUpgrade linux-image-5.3.0-1004-azureUpgrade linux-image-5.3.0-19-lowlatencyUpgrade linux-image-gkeUpgrade linux-image-5.3.0-19-snapdragonUpgrade linux-image-raspi2Upgrade linux-image-awsUpgrade linux-image-kvmUpgrade linux-image-5.3.0-19-generic-lpaeUpgrade linux-image-lowlatencyUpgrade linux-image-azureUpgrade linux-image-gcpUpgrade linux-image-5.3.0-1004-kvmUpgrade linux-image-generic-lpae | Oct 22, 2019 | Oct 18, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub