Lucene search

K
cvelistFlexeraCVELIST:CVE-2019-8956
HistoryApr 01, 2019 - 6:39 p.m.

CVE-2019-8956

2019-04-0118:39:32
flexera
www.cve.org
1

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

20.6%

In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the “sctp_sendmsg()” function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.

CNA Affected

[
  {
    "product": "Linux Kernel",
    "vendor": "UNKNOWN",
    "versions": [
      {
        "status": "affected",
        "version": "4.20.x prior to 4.20.8"
      },
      {
        "status": "affected",
        "version": "4.19.x prior to 4.19.21"
      }
    ]
  }
]

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

20.6%