CVE-2019-15666

Updated: 2023-12-06

CWE: Out-of-bounds Read

Description:

An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation.

CVSS3: 4.4


Vendor State

OS Vendor version Errata
Ubuntu 18.04 4.15.0-60.67 USN-4115-1
Ubuntu 18.04 AWS 4.15.0-1047.49 USN-4118-1
Ubuntu 16.04 HWE 4.15.0-60.67~16.04.1 USN-4115-1
Ubuntu 16.04 AWS HWE 4.15.0-1047.49~16.04.1 USN-4118-1
Debian 8 backports 4.9.189-3~deb8u1 DLA-1919-1
Oracle Linux 6 UEK 4 4.1.12-124.32.1.el6uek ELSA-2019-4808
Oracle Linux 7 UEK 4 4.1.12-124.32.1.el7uek ELSA-2019-4808
Ubuntu 16.04 GCP 4.15.0-1041.43 USN-4115-1
RHEL 8 4.18.0-147.el8 RHSA-2019:3517
Oracle Linux 7 UEK 5 4.14.35-1902.6.6.el7uek ELSA-2019-4820
Ubuntu 18.04 Azure 5.0.0-1018.19~18.04.1 USN-4114-1
Ubuntu 16.04 Azure 4.15.0-1056.61 USN-4115-1
CentOS 8 4.18.0-147.el8 CESA-2019:3517

KernelCare State

OS Original kernel version State
Ubuntu 18.04
4.15.0-54.58 show all hide all
4.15.0-42.45 4.15.0-52.56 4.15.0-33.36 4.15.0-44.47 4.15.0-24.26 4.15.0-51.55 4.15.0-36.39 4.15.0-34.37 4.15.0-39.42 4.15.0-47.50 4.15.0-58.64 4.15.0-43.46 4.15.0-32.35 4.15.0-46.49 4.15.0-31.33 4.15.0-35.38 4.15.0-38.41 4.15.0-45.48 4.15.0-48.51 4.15.0-53.57 4.15.0-56.62 4.15.0-20.21 4.15.0-29.31 4.15.0-23.25 4.15.0-55.60 4.15.0-50.54 4.15.0-22.24 4.15.0-30.32
Released
Ubuntu 18.04 AWS
4.15.0-1034.36 show all hide all
4.15.0-1044.46 4.15.0-1027.27 4.15.0-1021.21 4.15.0-1031.33 4.15.0-1032.34 4.15.0-1023.23 4.15.0-1029.30 4.15.0-1035.37 4.15.0-1037.39 4.15.0-1033.35 4.15.0-1041.43 4.15.0-1039.41 4.15.0-1043.45 4.15.0-1045.47 4.15.0-1040.42
Released
Ubuntu 16.04 HWE
4.15.0-24.26~16.04.1 show all hide all
4.15.0-34.37~16.04.1 4.15.0-47.50~16.04.1 4.15.0-39.42~16.04.1 4.15.0-42.45~16.04.1 4.15.0-46.49~16.04.1 4.15.0-58.64~16.04.1 4.15.0-33.36~16.04.1 4.15.0-45.48~16.04.1 4.15.0-30.32~16.04.1 4.15.0-36.39~16.04.1 4.15.0-55.60~16.04.2 4.15.0-50.54~16.04.1 4.15.0-52.56~16.04.1 4.15.0-51.55~16.04.1 4.15.0-54.58~16.04.1 4.15.0-29.31~16.04.1 4.15.0-48.51~16.04.1 4.15.0-35.38~16.04.1 4.15.0-38.41~16.04.1 4.15.0-32.35~16.04.1 4.15.0-43.46~16.04.1
Released
Ubuntu 16.04 AWS HWE
4.15.0-1039.41~16.04.1 show all hide all
4.15.0-1041.43~16.04.1 4.15.0-1033.35~16.04.1 4.15.0-1040.42~16.04.1 4.15.0-1032.34~16.04.1 4.15.0-1036.38~16.04.1 4.15.0-1044.46~16.04.1 4.15.0-1030.31~16.04.1 4.15.0-1035.37~16.04.1 4.15.0-1031.33~16.04.1 4.15.0-1045.47~16.04.1 4.15.0-1043.45~16.04.1
Released
Debian 9
4.9.82-1+deb9u2 show all hide all
4.9.168-1+deb9u2 4.9.110-3+deb9u3 4.9.107-1 4.9.30-2+deb9u1 4.9.168-1+deb9u5 4.9.168-1+deb9u4 4.9.110-3+deb9u2 4.9.168-1+deb9u3 4.9.88-1 4.9.110-3+deb9u1 4.9.88-1+deb9u1 4.9.51-1 4.9.110-1 4.9.30-2+deb9u5 4.9.65-1 4.9.80-1 4.9.30-2+deb9u4 4.9.65-3+deb9u1 4.9.130-1 4.9.30-2+deb9u3 4.9.110-3 4.9.130-2 4.9.144-3.1 4.9.144-3 4.9.30-2+deb9u2 4.9.30-2 4.9.65-3+deb9u2 4.9.65-3 4.9.110-2 4.9.110-3+deb9u4 4.9.144-2 4.9.80-2 4.9.82-1+deb9u3 4.9.168-1 4.9.135-1 4.9.110-3+deb9u6 4.9.110-3+deb9u5
Released
Debian 8 backports
4.9.144-3.1~deb8u1 show all hide all
4.9.110-1~deb8u1 4.9.110-3+deb9u4~deb8u1 4.9.110-3+deb9u5~deb8u1 4.9.168-1+deb9u3~deb8u1 4.9.168-1+deb9u4~deb8u1 4.9.168-1+deb9u5~deb8u1 4.9.30-2+deb9u2~bpo8+1 4.9.30-2+deb9u5~bpo8+1 4.9.30-2~bpo8+1 4.9.51-1~bpo8+1 4.9.65-3+deb9u1~bpo8+1 4.9.65-3+deb9u2~bpo8+1 4.9.65-3~bpo8+1 4.9.82-1+deb9u3~bpo8+1 4.9.88-1+deb9u1~bpo8+1 4.9.88-1~bpo8+1 4.9.110-3+deb9u1~deb8u1 4.9.110-3+deb9u2~deb8u1
Released
Oracle Linux 6 UEK 4
4.1.12-124.23.2.el6uek show all hide all
4.1.12-124.14.1.el6uek 4.1.12-124.21.1.el6uek 4.1.12-124.29.3.el6uek 4.1.12-124.25.1.el6uek 4.1.12-124.27.1.el6uek 4.1.12-124.15.2.el6uek 4.1.12-124.18.5.el6uek 4.1.12-112.16.7.el6uek 4.1.12-124.14.5.el6uek 4.1.12-124.19.1.el6uek 4.1.12-94.3.5.el6uek 4.1.12-124.29.3.1.el6uek 4.1.12-124.17.1.el6uek 4.1.12-103.9.4.el6uek 4.1.12-124.20.7.el6uek 4.1.12-124.16.2.el6uek 4.1.12-124.27.2.el6uek 4.1.12-124.18.9.el6uek 4.1.12-124.15.1.el6uek 4.1.12-124.19.2.el6uek 4.1.12-124.26.10.el6uek 4.1.12-124.28.1.el6uek 4.1.12-124.15.4.el6uek 4.1.12-124.28.6.el6uek 4.1.12-124.28.3.el6uek 4.1.12-112.14.13.el6uek 4.1.12-124.14.2.el6uek 4.1.12-124.16.4.el6uek 4.1.12-124.30.1.el6uek 4.1.12-124.26.12.el6uek 4.1.12-124.20.1.el6uek 4.1.12-112.14.15.el6uek 4.1.12-112.16.4.el6uek 4.1.12-112.17.3.el6uek 4.1.12-124.14.3.el6uek 4.1.12-124.17.2.el6uek 4.1.12-124.18.1.el6uek 4.1.12-124.20.3.el6uek 4.1.12-124.29.4.1.el6uek 4.1.12-124.31.1.el6uek 4.1.12-61.47.1.el6uek 4.1.12-124.16.1.el6uek 4.1.12-124.16.3.el6uek 4.1.12-124.22.2.el6uek 4.1.12-124.28.5.el6uek 4.1.12-124.31.1.1.el6uek
Released
Oracle Linux 7 UEK 4
4.1.12-124.23.2.el7uek show all hide all
4.1.12-124.25.1.el7uek 4.1.12-124.26.12.el7uek 4.1.12-124.15.2.el7uek 4.1.12-103.9.4.el7uek 4.1.12-124.28.3.el7uek 4.1.12-112.14.13.el7uek 4.1.12-124.15.1.el7uek 4.1.12-124.17.1.el7uek 4.1.12-112.16.7.el7uek 4.1.12-124.27.2.el7uek 4.1.12-124.28.6.el7uek 4.1.12-124.29.3.el7uek 4.1.12-124.14.2.el7uek 4.1.12-124.28.1.el7uek 4.1.12-124.15.4.el7uek 4.1.12-94.3.5.el7uek 4.1.12-124.16.2.el7uek 4.1.12-124.30.1.el7uek 4.1.12-124.14.5.el7uek 4.1.12-124.29.3.1.el7uek 4.1.12-124.14.1.el7uek 4.1.12-124.26.10.el7uek 4.1.12-124.27.1.el7uek 4.1.12-124.20.7.el7uek 4.1.12-124.18.9.el7uek 4.1.12-124.16.4.el7uek 4.1.12-112.16.4.el7uek 4.1.12-124.16.1.el7uek 4.1.12-124.16.3.el7uek 4.1.12-124.18.1.el7uek 4.1.12-124.20.3.el7uek 4.1.12-124.31.1.el7uek 4.1.12-112.14.15.el7uek 4.1.12-112.17.3.el7uek 4.1.12-124.14.3.el7uek 4.1.12-124.17.2.el7uek 4.1.12-124.22.2.el7uek 4.1.12-124.28.5.el7uek 4.1.12-124.29.4.1.el7uek 4.1.12-124.31.1.1.el7uek
Released
Proxmox VE 5
4.15.18-11-pve_4.15.18-33 show all hide all
4.15.18-6-pve_4.15.18-25 4.15.18-8-pve_4.15.18-28 4.15.18-1-pve_4.15.18-15 4.15.18-2-pve_4.15.18-20 4.15.18-18-pve_4.15.18-44 4.15.18-16-pve_4.15.18-41 4.15.17-3-pve_4.15.17-12 4.15.18-10-pve_4.15.18-32 4.15.18-12-pve_4.15.18-35 4.15.18-14-pve-4.15.18-38 4.15.18-7-pve-4.15.18-27 4.15.10-1-pve_4.15.10-4 4.15.15-1-pve_4.15.15-6 4.15.17-1-pve_4.15.17-9 4.15.17-2-pve_4.15.17-10 4.15.18-1-pve_4.15.18-16 4.15.18-1-pve_4.15.18-17 4.15.18-1-pve_4.15.18-19 4.15.18-10-pve_4.15.18-31 4.15.18-11-pve_4.15.18-34 4.15.18-13-pve_4.15.18-37 4.15.18-17-pve_4.15.18-42 4.15.18-17-pve_4.15.18-43 4.15.18-19-pve_4.15.18-45 4.15.18-4-pve_4.15.18-23 4.15.18-7-pve_4.15.18-26 4.15.3-1-pve_4.15.3-1 4.15.18-2-pve_4.15.18-21 4.15.18-9-pve_4.15.18-30 4.15.18-14-pve_4.15.18-39 4.15.18-20-pve_4.15.18-46 4.15.18-15-pve_4.15.18-40 4.15.18-3-pve_4.15.18-22 4.15.18-5-pve_4.15.18-24
Released
Ubuntu 18.04 GCP
4.15.0-1010.10 show all hide all
4.15.0-1015.15 4.15.0-1025.26 4.15.0-1024.25 4.15.0-1018.19 4.15.0-1029.31 4.15.0-1026.27 4.15.0-1028.29 4.15.0-1021.22 4.15.0-1017.18 4.15.0-1009.9 4.15.0-1033.35 4.15.0-1032.34 4.15.0-1036.38 4.15.0-1008.8 4.15.0-1034.36 4.15.0-1006.6 4.15.0-1030.32 4.15.0-1014.14 4.15.0-1040.42 4.15.0-1027.28 4.15.0-1019.20 4.15.0-1037.39
Released
Ubuntu 16.04 GCP
4.15.0-1032.34~16.04.1 show all hide all
4.15.0-1024.25~16.04.2 4.15.0-1040.42~16.04.1 4.15.0-1021.22~16.04.1 4.15.0-1019.20~16.04.1 4.15.0-1036.38~16.04.1 4.15.0-1017.18~16.04.1 4.15.0-1018.19~16.04.2 4.15.0-1029.31~16.04.1 4.15.0-1028.29~16.04.1 4.15.0-1033.35~16.04.1 4.15.0-1014.14~16.04.1 4.15.0-1026.27~16.04.1 4.15.0-1025.26~16.04.1 4.15.0-1034.36~16.04.1 4.15.0-1027.28~16.04.1 4.15.0-1015.15~16.04.1 4.15.0-1037.39~16.04.1
Released
CentOS 6 alt
4.9.54-29.el6 show all hide all
3.18.21-17.el6 3.18.25-18.el6 3.18.25-19.el6 3.18.30-20.el6 3.18.32-20.el6 3.18.34-20.el6 3.18.41-20.el6 3.18.44-20.el6 4.9.11-22.el6 4.9.13-22.el6 4.9.15-22.el6 4.9.25-27.el6 4.9.34-29.el6 4.9.39-29.el6 4.9.44-29.el6 4.9.48-29.el6 4.9.63-29.el6 3.18.21-16.el6 4.9.23-26.el6 4.9.58-29.el6
Released
CentOS 7 alt
4.9.54-29.el7 show all hide all
3.18.21-17.el7 3.18.25-18.el7 3.18.25-19.el7 3.18.30-20.el7 3.18.32-20.el7 3.18.34-20.el7 3.18.41-20.el7 3.18.44-20.el7 4.9.11-22.el7 4.9.15-22.el7 4.9.23-26.el7 4.9.25-27.el7 4.9.31-27.el7 4.9.34-29.el7 4.9.39-29.el7 4.9.44-29.el7 4.9.48-29.el7 4.9.58-29.el7 4.9.63-29.el7 3.18.21-16.el7 4.9.13-22.el7
Released
RHEL 8
4.18.0-80.7.1.el8_0 show all hide all
4.18.0-80.11.2.el8_0 4.18.0-80.1.2.el8_0 4.18.0-80.7.2.el8_0 4.18.0-80.4.2.el8_0 4.18.0-80.11.1.el8_0 4.18.0-80.el8
Released
Debian 10
4.19.37-5 show all hide all
4.19.37-5+deb10u2 4.19.37-5+deb10u1
Released
Proxmox VE 6
5.0.18-1-pve_5.0.18-3 show all hide all
5.0.15-1-pve_5.0.15-1 5.0.12-1-pve_5.0.12-1 5.0.18-1-pve_5.0.18-1 5.0.18-1-pve_5.0.18-2 5.0.8-1-pve_5.0.8-1 5.0.8-2-pve_5.0.8-2
Released
Endurance 7 eig 4.14
Ready For Release
Proofpoint
Ready For Release
Oracle Linux 7 UEK 5
4.14.35-1902.2.0.el7uek show all hide all
4.14.35-1844.2.5.el7uek 4.14.35-1902.3.1.el7uek 4.14.35-1844.3.2.el7uek 4.14.35-1818.4.5.el7uek 4.14.35-1844.4.5.el7uek 4.14.35-1818.5.4.el7uek 4.14.35-1818.2.1.el7uek 4.14.35-1818.4.6.el7uek 4.14.35-1818.4.7.el7uek 4.14.35-1844.0.7.el7uek 4.14.35-1844.4.5.2.el7uek 4.14.35-1902.0.18.el7uek 4.14.35-1902.3.2.el7uek 4.14.35-1902.5.1.4.el7uek 4.14.35-1902.5.1.5.el7uek 4.14.35-1902.5.2.1.el7uek 4.14.35-1902.5.2.2.el7uek 4.14.35-1902.5.2.el7uek 4.14.35-1844.1.3.el7uek 4.14.35-1818.3.3.el7uek 4.14.35-1902.4.8.el7uek 4.14.35-1844.5.3.el7uek
Released
Ubuntu 18.04 Azure
4.15.0-1014.14 show all hide all
4.15.0-1037.39 4.15.0-1031.32 4.15.0-1025.26 4.15.0-1012.12 4.15.0-1021.21 4.15.0-1022.23 4.15.0-1009.9 4.15.0-1018.18 4.15.0-1030.31 4.15.0-1032.33 4.15.0-1028.29 4.15.0-1035.36 4.15.0-1019.19 4.15.0-1023.24 4.15.0-1013.13 4.15.0-1036.38
Released
Ubuntu 16.04 Azure
4.15.0-1018.18~16.04.1 show all hide all
4.15.0-1030.31~16.04.1 4.15.0-1050.55 4.15.0-1041.45 4.15.0-1051.56 4.15.0-1036.38~16.04.1 4.15.0-1025.26~16.04.1 4.15.0-1049.54 4.15.0-1037.39~16.04.1 4.15.0-1019.19~16.04.1 4.15.0-1023.24~16.04.1 4.15.0-1014.14~16.04.1 4.15.0-1022.22~16.04.1 4.15.0-1047.51 4.15.0-1055.60 4.15.0-1035.36~16.04.1 4.15.0-1045.49 4.15.0-1021.21~16.04.1 4.15.0-1031.32~16.04.1 4.15.0-1040.44 4.15.0-1028.29~16.04.1 4.15.0-1032.33~16.04.1 4.15.0-1039.43 4.15.0-1042.46 4.15.0-1052.57 4.15.0-1013.13~16.04.2 4.15.0-1046.50
Released
CentOS 8
4.18.0-80.7.1.el8_0 show all hide all
4.18.0-80.11.1.el8_0 4.18.0-80.7.2.el8_0 4.18.0-80.11.2.el8_0 4.18.0-80.el8 4.18.0-80.1.2.el8_0 4.18.0-80.4.2.el8_0
Released
CloudLinux OS 7h
4.18.0-80.7.2.el7h
Released
Debian 10 cloud
4.19.28-2_bpo9+1
Released