Review reviewHigh

CVE-2019-25160

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both errors are embarassingly simple, and the fixes are straightforward. As a FYI for anyone backporting this patch to kernels prior to v4.8, you'll want to apply the netlbl_bitmap_walk() patch to cipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before Linux v4.8.

CVSS
7.1
EPSS
0.74%
51.3% percentile
CISA KEV
Not listed
Published
2024.02.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.74%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both errors are embarassingly simple, and the fixes are straightforward. As a FYI for anyone backporting this patch to kernels prior to v4.8, you'll want to apply the netlbl_bitmap_walk() patch to cipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before Linux v4.8.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < 97bc3683c24999ee621d847c9348c75d2fe86272, >= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < c61d01faa5550e06794dcf86125ccd325bfad950, >= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < dc18101f95fa6e815f426316b8b9a5cee28a334e, >= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < 1c973f9c7cc2b3caae93192fdc8ecb3f0b4ac000, >= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < fcfe700acdc1c72eab231300e82b962bac2b2b2c, >= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < e3713abc4248aa6bcc11173d754c418b02a62cbb, >= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < fbf9578919d6c91100ec63acf2cba641383f6c78, >= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < 5578de4834fe0f2a34fedc7374be691443396d1f, >= 2.6.19, >= 2.6.19 < 3.16.66, >= 3.17.0 < 3.18.137, >= 3.19.0 < 4.4.177, >= 4.5.0 < 4.9.163, >= 4.10.0 < 4.14.106, >= 4.15.0 < 4.19.28, >= 4.20.0 < 4.20.15
Fixed versions
3.16.66, 3.18.137, 4.4.177, 4.9.163, 4.14.106, 4.19.28, 4.20.15

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125
CVE-2019-25160 — Linux Linux, linux kernel | SECUFOCUS NOW