Input validation error in Linux kernel - CVE-2019-5108

 

Input validation error in Linux kernel - CVE-2019-5108

Published: December 23, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30501
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5108
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby APs of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Real Time
Slackware Linux
kernel-rt (Red Hat package)
linux-4.4.217/kernel-generic
linux-4.4.217/kernel-huge
linux-4.4.217/kernel-modules
linux-4.4.217/kernel-headers
kernel-alt (Red Hat package)

How to mitigate CVE-2019-5108

Install update from vendor's website.

Linux kernel - update to 5.3
kernel-rt (Red Hat package) - update to 3.10.0-1127.19.1.rt56.1116.el7
linux-4.4.217/kernel-generic - update to 4.4.217
linux-4.4.217/kernel-huge - update to 4.4.217
linux-4.4.217/kernel-modules - update to 4.4.217
linux-4.4.217/kernel-headers - update to 4.4.217_smp
kernel-alt (Red Hat package) - update to 4.14.0-115.19.1.el7a

External References

Related Security Bulletins