Wind River Support Network

HomeDefectsLIN1018-3759
Fixed

LIN1018-3759 : Security Advisory - linux - CVE-2019-9162

Created: Mar 27, 2019    Updated: Apr 1, 2019
Resolved Date: Mar 29, 2019
Found In Version: unknown
Fix Version: 10.18.44.5
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Kernel

Description

In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-9162 User=admin}

CVEs


Live chat
Online