9.8

CVE-2019-18805

An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.4 < 4.4.180
Linux ≫ Linux Kernel Version >= 4.9 < 4.9.172
Linux ≫ Linux Kernel Version >= 4.14 < 4.14.115
Linux ≫ Linux Kernel Version >= 4.19 < 4.19.38
Linux ≫ Linux Kernel Version >= 5.0 < 5.0.11
Linux ≫ Linux Kernel Version 5.1 Update rc1
Linux ≫ Linux Kernel Version 5.1 Update rc2
Linux ≫ Linux Kernel Version 5.1 Update rc3
Linux ≫ Linux Kernel Version 5.1 Update rc4
Linux ≫ Linux Kernel Version 5.1 Update rc5
Linux ≫ Linux Kernel Version 5.1 Update rc6
Linux ≫ Linux Kernel Version 5.1 Update rc7
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Redhat ≫ Enterprise Linux Version 7.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ E-series Santricity Os Controller Version >= 11.0.0 <= 11.60.3
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Netapp ≫ Hci Compute Node Version -
Netapp ≫ Hci Storage Node Version -
Netapp ≫ Aff A700s Firmware Version -
   Netapp ≫ Aff A700s Version -
Netapp ≫ Fas8300 Firmware Version -
   Netapp ≫ Fas8300 Version -
Netapp ≫ Fas8700 Firmware Version -
   Netapp ≫ Fas8700 Version -
Netapp ≫ Aff A400 Firmware Version -
   Netapp ≫ Aff A400 Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.43% 0.874
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

https://access.redhat.com/errata/RHSA-2020:0740
Third Party Advisory
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.11
Patch
Vendor Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00039.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20191205-0001/
Third Party Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=19fad20d15a6494f47f85d869f00b11343ee5c78
Patch
Vendor Advisory
Mailing List