CVE-2019-20795

Name
CVE-2019-20795
Description
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://git.kernel.org/pub/scm/network/iproute2/iproute2.git/commit/?id=9bf2c538a0eb10d66e2365a655bf6c52f5ba3d10
Issue Tracking https://bugzilla.suse.com/show_bug.cgi?id=1171452
Third Party Advisory https://usn.ubuntu.com/4357-1/
Third Party Advisory https://security.gentoo.org/glsa/202008-06

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:iproute2_project:iproute2:*:*:*:*:*:*:*:* iproute2 >= None < 5.1.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
iproute2 3.10-main 4.20.0-r2 Natanael Copa <ncopa@alpinelinux.org> fixed