imPC@ndo IT

Tracker / CVE-2019-20054

CVE-2019-20054

Medium 5.5

In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links, aka CID-23da9588037e.

Affected products and versions

linux linux_kernel · … → 5.0.6
netapp 8300_firmware
netapp 8700_firmware
netapp a400_firmware
netapp active_iq_unified_manager
netapp cloud_backup
netapp data_availability_services
netapp e-series_santricity_os_controller · 11.0 → 11.70.2
netapp fas\/aff_baseboard_management_controller
netapp h610s_firmware
netapp solidfire_\&_hci_management_node
netapp solidfire_baseboard_management_controller
netapp steelstore_cloud_integrated_storage

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References