In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-18540 In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.
Ubuntu USN Ubuntu USN USN-3930-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3930-2 Linux kernel (HWE) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T21:38:46.546Z

Reserved: 2019-02-25T00:00:00

Link: CVE-2019-9162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-02-25T23:29:01.330

Modified: 2024-11-21T04:51:06.840

Link: CVE-2019-9162

cve-icon Redhat

Severity : Important

Publid Date: 2019-02-11T00:00:00Z

Links: CVE-2019-9162 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses