Vulnerability Description
An issue was discovered in the Linux kernel through 5.2.13. nbd_genl_status in drivers/block/nbd.c does not check the nla_nest_start_noflag return value.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 5.2.13 |
Related Weaknesses (CWE)
References
- https://lore.kernel.org/patchwork/patch/1106884/Mailing ListPatchVendor Advisory
- https://lore.kernel.org/patchwork/patch/1126650/PatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20191004-0001/Third Party Advisory
- https://support.f5.com/csp/article/K03814795?utm_source=f5support&%3Butm_medi
- https://usn.ubuntu.com/4414-1/
- https://usn.ubuntu.com/4425-1/
- https://usn.ubuntu.com/4439-1/
- https://usn.ubuntu.com/4440-1/
- https://lore.kernel.org/patchwork/patch/1106884/Mailing ListPatchVendor Advisory
- https://lore.kernel.org/patchwork/patch/1126650/PatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20191004-0001/Third Party Advisory
- https://support.f5.com/csp/article/K03814795?utm_source=f5support&%3Butm_medi
- https://usn.ubuntu.com/4414-1/
- https://usn.ubuntu.com/4425-1/
- https://usn.ubuntu.com/4439-1/
FAQ
What is CVE-2019-16089?
CVE-2019-16089 is a vulnerability with a CVSS score of 4.1 (MEDIUM). An issue was discovered in the Linux kernel through 5.2.13. nbd_genl_status in drivers/block/nbd.c does not check the nla_nest_start_noflag return value.
How severe is CVE-2019-16089?
CVE-2019-16089 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16089?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.