ISOMAN

CVE

CVE-2019-16714

In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://www.openwall.com/lists/oss-security/2019/09/24/2
  2. http://www.openwall.com/lists/oss-security/2019/09/25/1
  3. https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.14
  4. https://github.com/torvalds/linux/commit/7d0a06586b2686ba80c4a2da5f91cb10ffbea736
  5. https://security.netapp.com/advisory/ntap-20191031-0005/
  6. https://support.f5.com/csp/article/K48351130?utm_source=f5support&amp%3Butm_medium=RSS
  7. https://usn.ubuntu.com/4157-1/
  8. https://usn.ubuntu.com/4157-2/
  9. http://www.openwall.com/lists/oss-security/2019/09/24/2
  10. http://www.openwall.com/lists/oss-security/2019/09/25/1
  11. https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.14
  12. https://github.com/torvalds/linux/commit/7d0a06586b2686ba80c4a2da5f91cb10ffbea736
  13. https://security.netapp.com/advisory/ntap-20191031-0005/
  14. https://support.f5.com/csp/article/K48351130?utm_source=f5support&amp%3Butm_medium=RSS
  15. https://usn.ubuntu.com/4157-1/
  16. https://usn.ubuntu.com/4157-2/