ISOMAN

CVE

CVE-2019-5108

An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby APs of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LSN-0063-1.html
  2. https://git.kernel.org/linus/3e493173b7841259a08c5c8e5cbe90adb349da7e
  3. https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html
  4. https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
  5. https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html
  6. https://security.netapp.com/advisory/ntap-20200204-0002/
  7. https://talosintelligence.com/vulnerability_reports/TALOS-2019-0900
  8. https://usn.ubuntu.com/4285-1/
  9. https://usn.ubuntu.com/4286-1/
  10. https://usn.ubuntu.com/4286-2/
  11. https://usn.ubuntu.com/4287-1/
  12. https://usn.ubuntu.com/4287-2/
  13. https://www.debian.org/security/2020/dsa-4698
  14. https://www.oracle.com/security-alerts/cpuApr2021.html
  15. http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LSN-0063-1.html
  16. https://git.kernel.org/linus/3e493173b7841259a08c5c8e5cbe90adb349da7e
  17. https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html
  18. https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
  19. https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html
  20. https://security.netapp.com/advisory/ntap-20200204-0002/