CVE-2019-9162

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 4.6 (Medium)
46% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 7
Advisories 4

In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.

Weaknesses
CWE-787
Out-of-bounds Write
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2019-02-25 23:29:01
(5 years ago)
Updated Date
2022-04-05 20:46:50
(2 years ago)

Affected Products

Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Linux Kernel from 4.19 version and prior 4.19.25 version cpe:2.3:o:linux:linux_kernel >= 4.19 < 4.19.25
OR  
  Running on/with
  Linux Kernel from 4.20 version and prior 4.20.12 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 4.20.12

Configuration #2

AND
    CPE23 From Up To
OR  
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
OR  
  Running on/with
  Netapp Snapprotect cpe:2.3:a:netapp:snapprotect:-
OR  
  Running on/with
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-

Configuration #3

AND
    CPE23 From Up To
OR  
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts
OR  
  Running on/with
  Canonical Ubuntu Linux 18.10 cpe:2.3:o:canonical:ubuntu_linux:18.10

Configuration #4

AND
    CPE23 From Up To
OR  
  Netapp Cn1610 Firmware cpe:2.3:o:netapp:cn1610_firmware:-
OR  
  Running on/with
  Netapp Cn1610 cpe:2.3:h:netapp:cn1610:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...