CVE-2019-5108

NameCVE-2019-5108
DescriptionAn exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby APs of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)jessie3.16.56-1+deb8u1vulnerable
jessie (security)3.16.81-1vulnerable
stretch4.9.189-3vulnerable
stretch (security)4.9.189-3+deb9u2vulnerable
buster4.19.67-2+deb10u1vulnerable
buster (security)4.19.67-2+deb10u2vulnerable
bullseye, sid5.4.13-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsource(unstable)5.3.7-1

Notes

https://talosintelligence.com/vulnerability_reports/TALOS-2019-0900
https://git.kernel.org/linus/3e493173b7841259a08c5c8e5cbe90adb349da7e

Search for package or bug name: Reporting problems