CVE-2019-15666
An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation.
- Affected products
- Alt Linux, Centos, Linux Kernel, Red Hat, Suse
- Linux Linux Kernel
- < 5.0.19
- CVSS 2.0
- 4.9 MEDIUM
- CVSS 3.1
- 4.4 MEDIUM
- EPSS
- 1.7% (76th percentile)
- Weakness
- CWE-125
- NVD status
- Modified
- Published
- 2019-08-27
CVE-2019-15666 at NVD
1 known exploit for CVE-2019-15666
Proof-of-concept code and exploit modules indexed by Sploitus