668
VMScore

CVE-2019-18805

Published: 07/11/2019 Updated: 22/06/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in net/ipv4/sysctl_net_ipv4.c in the Linux kernel prior to 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 5.1

linux linux kernel

opensuse leap 15.0

opensuse leap 15.1

redhat enterprise linux 7.0

netapp steelstore cloud integrated storage -

netapp data availability services -

netapp solidfire -

netapp hci management node -

netapp hci storage node -

netapp active iq unified manager -

netapp hci compute node -

netapp e-series santricity os controller

broadcom fabric operating system -

netapp aff a700s firmware -

netapp fas8300 firmware -

netapp fas8700 firmware -

netapp aff a400 firmware -

netapp h610s firmware -

Vendor Advisories

Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Important: kernel-alt security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel-alt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System ...