CVE-2019-15239

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnection and re-connection, a local attacker can trigger multiple use-after-free conditions. This can result in a kernel crash, or potentially in privilege escalation. NOTE: this affects (for example) Linux distributions that use 4.9.x longterm kernels before 4.9.190 or 4.14.x longterm kernels before 4.14.139.

References

http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html

http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7f582b248d0a86bae5788c548d7bb5bca6f7691a

https://lore.kernel.org/stable/[email protected]/

https://pulsesecurity.co.nz/advisories/linux-kernel-4.9-tcpsocketsuaf

https://salsa.debian.org/kernel-team/kernel-sec/blob/f6273af2d956a87296b6b60379d0a186c9be4bbc/active/CVE-2019-15239

https://www.debian.org/security/2019/dsa-4497

Details

Source: MITRE

Published: 2019-08-20

Updated: 2019-09-24

Type: CWE-416

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Tenable Plugins

View all (26 total)

IDNameProductFamilySeverity
151419EulerOS Virtualization 3.0.2.2 : kernel (EulerOS-SA-2021-2140)NessusHuawei Local Security Checks
high
144831EulerOS Virtualization 3.0.2.6 : kernel (EulerOS-SA-2021-1056)NessusHuawei Local Security Checks
critical
136910NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2020-0028)NessusNewStart CGSL Local Security Checks
high
133463Virtuozzo 7 : readykernel-patch (VZA-2019-086)NessusVirtuozzo Local Security Checks
high
132686RHEL 7 : kpatch-patch (RHSA-2020:0027)NessusRed Hat Local Security Checks
high
132005SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3258-1)NessusSuSE Local Security Checks
high
132000SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3230-1)NessusSuSE Local Security Checks
high
131999SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3228-1)NessusSuSE Local Security Checks
high
131832Scientific Linux Security Update : kernel on SL7.x x86_64 (20191205)NessusScientific Linux Local Security Checks
high
131571CentOS 7 : kernel (CESA-2019:3979)NessusCentOS Local Security Checks
high
131519Oracle Linux 7 : kernel (ELSA-2019-3979)NessusOracle Linux Local Security Checks
high
131379RHEL 7 : kernel (RHSA-2019:3979)NessusRed Hat Local Security Checks
high
131378RHEL 7 : kernel-rt (RHSA-2019:3978)NessusRed Hat Local Security Checks
high
130949SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2949-1)NessusSuSE Local Security Checks
critical
130736EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2274)NessusHuawei Local Security Checks
critical
130663EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-2201)NessusHuawei Local Security Checks
critical
130163SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2738-1)NessusSuSE Local Security Checks
critical
129845SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2648-1)NessusSuSE Local Security Checks
critical
129551Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2019-4810)NessusOracle Linux Local Security Checks
high
129345openSUSE Security Update : the Linux Kernel (openSUSE-2019-2181)NessusSuSE Local Security Checks
critical
129339openSUSE Security Update : the Linux Kernel (openSUSE-2019-2173)NessusSuSE Local Security Checks
critical
129157SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2424-1)NessusSuSE Local Security Checks
critical
129156SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2414-1)NessusSuSE Local Security Checks
critical
129154SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2019:2412-1)NessusSuSE Local Security Checks
critical
128725Photon OS 2.0: Linux PHSA-209-2.0-0175NessusPhotonOS Local Security Checks
critical
127867Debian DSA-4497-1 : linux - security updateNessusDebian Local Security Checks
high