peter bassill · operator
$ cve CVE-2019-18805 JSON

CVE-2019-18805

9.8
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.43% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2019-11-07
Last modified2026-06-17

Affected (22)

VendorProduct
broadcomfabric operating system
linuxlinux kernel
netappactive iq unified manager
netappaff a400
netappaff a400 firmware
netappaff a700s
netappaff a700s firmware
netappdata availability services
netappe-series santricity os controller
netappfas8300
netappfas8300 firmware
netappfas8700
netappfas8700 firmware
netapph610s
netapph610s firmware
netapphci compute node
netapphci management node
netapphci storage node
netappsolidfire
netappsteelstore cloud integrated storage
opensuseleap
redhatenterprise linux

References

→ the Explorer  ·  watch your stack  ·  NVD