Vulnerability Name:

CVE-2019-17052 (CCN-168359)

Assigned:2019-09-24
Published:2019-09-24
Updated:2022-10-07
Summary:ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768.
CVSS v3 Severity:3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-276
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2019-17052

Source: MISC
Type: Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html

Source: XF
Type: UNKNOWN
linux-kernel-cve201917052-sec-bypass(168359)

Source: MISC
Type: Mailing List, Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=2c675dab816278a1724c1e93b384c2f05a11cb31

Source: MISC
Type: Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0614e2b73768b502fc32a75349823356d98aae2c

Source: CCN
Type: Linux Kernel GIT Repository
Merge branch 'check-CAP_NEW_RAW'

Source: MISC
Type: Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0edc3f703f7bcaf550774b5d43ab727bcd0fe06b

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2019-41e28660ae

Source: BUGTRAQ
Type: Mailing List, Patch, Third Party Advisory
20191108 [slackware-security] Slackware 14.2 kernel (SSA:2019-311-01)

Source: UBUNTU
Type: Third Party Advisory
USN-4184-1

Source: UBUNTU
Type: Third Party Advisory
USN-4185-1

Source: UBUNTU
Type: Third Party Advisory
USN-4185-2

Source: UBUNTU
Type: Third Party Advisory
USN-4186-1

Source: UBUNTU
Type: Third Party Advisory
USN-4186-2

Source: CCN
Type: IBM Security Bulletin 6116992 (Spectrum Protect Plus)
Multiple vulnerabilities in Linux Kernel affect IBM Spectrum Protect Plus

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version >= 3.16 and <= 5.3.2)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:29:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:5.3.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:spectrum_protect_plus:10.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_protect_plus:10.1.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201917052
    V
    CVE-2019-17052
    2022-09-02
    oval:org.opensuse.security:def:33109
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:34017
    P
    Security update for chrony (Moderate)
    2021-12-22
    oval:org.opensuse.security:def:30278
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:33052
    P
    Security update for openexr (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:31313
    P
    Security update for ruby2.1 (Important)
    2021-12-01
    oval:org.opensuse.security:def:31292
    P
    Security update for strongswan (Important)
    2021-10-19
    oval:org.opensuse.security:def:34552
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:34551
    P
    Security update for atftp (Moderate)
    2021-09-27
    oval:org.opensuse.security:def:31253
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:33960
    P
    Security update for cpio (Important)
    2021-08-23
    oval:org.opensuse.security:def:30223
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:34478
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:33941
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:31204
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:36085
    P
    apache2-mod_perl-2.0.4-40.24.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:34434
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:33645
    P
    Security update for samba (Important)
    2021-05-04
    oval:org.opensuse.security:def:33902
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:30070
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:34409
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:32896
    P
    Security update for xorg-x11-server (Important)
    2021-04-14
    oval:org.opensuse.security:def:33634
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:33633
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:31148
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:34647
    P
    Security update for wpa_supplicant (Important)
    2021-03-08
    oval:org.opensuse.security:def:33728
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:34563
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:35247
    P
    Security update for the Linux Kernel (Important)
    2021-01-15
    oval:org.opensuse.security:def:31357
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:28860
    P
    Security update for mutt (Important)
    2020-12-07
    oval:org.opensuse.security:def:36044
    P
    taglib-1.5-19.23.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:30553
    P
    Security update for Samba
    2020-12-01
    oval:org.opensuse.security:def:27993
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33197
    P
    log4net on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30542
    P
    Security update for kdelibs4
    2020-12-01
    oval:org.opensuse.security:def:27909
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:33158
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29889
    P
    Security update for SUSE Linux Enterprise Server 11 SP1 Kernel for Teradata (Important)
    2020-12-01
    oval:org.opensuse.security:def:30541
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27852
    P
    Security update for perl
    2020-12-01
    oval:org.opensuse.security:def:29853
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:27770
    P
    Security update for IBM Java
    2020-12-01
    oval:org.opensuse.security:def:29215
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:27642
    P
    Security update for LibreOffice
    2020-12-01
    oval:org.opensuse.security:def:29171
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27578
    P
    wireshark on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32809
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29154
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35156
    P
    Security update for the SUSE Linux Enterprise 11 SP3 Kernel for Teradata (Important)
    2020-12-01
    oval:org.opensuse.security:def:27567
    P
    silc-toolkit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32752
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29115
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:35116
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27566
    P
    sendmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32658
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29066
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:32523
    P
    gnutls on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29012
    P
    Security update for hawk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32445
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:32434
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:28776
    P
    Security update for libwmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34370
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31104
    P
    Security update for the SUSE Linux Enterprise 11 SP3 Kernel for Teradata (Important)
    2020-12-01
    oval:org.opensuse.security:def:32433
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:28719
    P
    Security update for kdebase4-workspace (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34321
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31067
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28634
    P
    Security update for augeas
    2020-12-01
    oval:org.opensuse.security:def:34263
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30429
    P
    Security update for xorg-x11-libxcb
    2020-12-01
    oval:org.opensuse.security:def:28503
    P
    Security update for openssh-openssl1 (Critical)
    2020-12-01
    oval:org.opensuse.security:def:34106
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:30385
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:28435
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30366
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28424
    P
    Security update for wireshark (Low)
    2020-12-01
    oval:org.opensuse.security:def:30327
    P
    Security update for tiff (Low)
    2020-12-01
    oval:org.opensuse.security:def:28423
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33864
    P
    Security update for jasper
    2020-12-01
    oval:org.opensuse.security:def:35406
    P
    Security update for openssh-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:35362
    P
    Security update for nagios-plugins
    2020-12-01
    oval:org.opensuse.security:def:35335
    P
    Security update for mozilla-nspr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29984
    P
    Security update for libsoup (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35296
    P
    Security update for libxml2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:32033
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29927
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31995
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29840
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:35188
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29708
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:35029
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:29635
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:34939
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:29624
    P
    Security update for Mono
    2020-12-01
    oval:org.opensuse.security:def:34882
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29016
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29623
    P
    Security update for bsdtar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34783
    P
    Recommended update for NetworkManager-kde4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28981
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28343
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30993
    P
    Security update for jasper
    2020-12-01
    oval:org.opensuse.security:def:28299
    P
    Security update for netatalk (Important)
    2020-12-01
    oval:org.opensuse.security:def:30906
    P
    Security update for freeradius-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28285
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30849
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28246
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30759
    P
    Security update for apache2-mod_nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28197
    P
    Security update for libexif (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33264
    P
    sysconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30627
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:28144
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:33220
    P
    opie on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.disco:def:2019170520000000
    V
    CVE-2019-17052 on Ubuntu 19.04 (disco) - medium.
    2019-10-01
    oval:com.ubuntu.bionic:def:2019170520000000
    V
    CVE-2019-17052 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-10-01
    oval:com.ubuntu.xenial:def:2019170520000000
    V
    CVE-2019-17052 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-10-01
    BACK
    linux linux kernel *
    debian debian linux 8.0
    fedoraproject fedora 29
    canonical ubuntu linux 18.04
    canonical ubuntu linux 19.04
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    linux linux kernel 5.3.2
    ibm spectrum protect plus 10.1.0
    ibm spectrum protect plus 10.1.5