UBUNTU-CVE-2019-8956

Source
https://ubuntu.com/security/CVE-2019-8956
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-8956.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2019-8956
Upstream
Downstream
Related
Published
2019-02-22T00:00:00Z
Modified
2025-07-18T16:45:02Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctpsendmsg()" function (net/sctp/socket.c) when handling SCTPSENDALL flag can be exploited to corrupt memory.

References

Affected packages

Ubuntu:18.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure@4.18.0-1014.14~18.04.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-1014.14~18.04.1

Affected versions

4.*

4.15.0-1002.2
4.15.0-1003.3
4.15.0-1004.4
4.15.0-1008.8
4.15.0-1009.9
4.15.0-1012.12
4.15.0-1013.13
4.15.0-1014.14
4.15.0-1018.18
4.15.0-1019.19
4.15.0-1021.21
4.15.0-1022.23
4.15.0-1023.24
4.15.0-1025.26
4.15.0-1028.29
4.15.0-1030.31
4.15.0-1031.32
4.15.0-1032.33
4.15.0-1035.36
4.15.0-1036.38
4.15.0-1037.39
4.18.0-1011.11~18.04.1
4.18.0-1013.13~18.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "linux-azure-cloud-tools-4.18.0-1014",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-azure-headers-4.18.0-1014",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-azure-tools-4.18.0-1014",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-buildinfo-4.18.0-1014-azure",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-cloud-tools-4.18.0-1014-azure",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-headers-4.18.0-1014-azure",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-image-unsigned-4.18.0-1014-azure",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-image-unsigned-4.18.0-1014-azure-dbgsym",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-modules-4.18.0-1014-azure",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-modules-extra-4.18.0-1014-azure",
            "binary_version": "4.18.0-1014.14~18.04.1"
        },
        {
            "binary_name": "linux-tools-4.18.0-1014-azure",
            "binary_version": "4.18.0-1014.14~18.04.1"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:18.04:LTS / linux-gcp-edge

Package

Name
linux-gcp-edge
Purl
pkg:deb/ubuntu/linux-gcp-edge@4.18.0-1008.9~18.04.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-1008.9~18.04.1

Affected versions

4.*

4.18.0-1004.5~18.04.1
4.18.0-1005.6~18.04.1
4.18.0-1006.7~18.04.1
4.18.0-1007.8~18.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "linux-buildinfo-4.18.0-1008-gcp",
            "binary_version": "4.18.0-1008.9~18.04.1"
        },
        {
            "binary_name": "linux-gcp-edge-tools-4.18.0-1008",
            "binary_version": "4.18.0-1008.9~18.04.1"
        },
        {
            "binary_name": "linux-gcp-headers-4.18.0-1008",
            "binary_version": "4.18.0-1008.9~18.04.1"
        },
        {
            "binary_name": "linux-headers-4.18.0-1008-gcp",
            "binary_version": "4.18.0-1008.9~18.04.1"
        },
        {
            "binary_name": "linux-image-unsigned-4.18.0-1008-gcp",
            "binary_version": "4.18.0-1008.9~18.04.1"
        },
        {
            "binary_name": "linux-image-unsigned-4.18.0-1008-gcp-dbgsym",
            "binary_version": "4.18.0-1008.9~18.04.1"
        },
        {
            "binary_name": "linux-modules-4.18.0-1008-gcp",
            "binary_version": "4.18.0-1008.9~18.04.1"
        },
        {
            "binary_name": "linux-modules-extra-4.18.0-1008-gcp",
            "binary_version": "4.18.0-1008.9~18.04.1"
        },
        {
            "binary_name": "linux-tools-4.18.0-1008-gcp",
            "binary_version": "4.18.0-1008.9~18.04.1"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:18.04:LTS / linux-hwe

Package

Name
linux-hwe
Purl
pkg:deb/ubuntu/linux-hwe@4.18.0-17.18~18.04.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-17.18~18.04.1

Affected versions

4.*

4.18.0-13.14~18.04.1
4.18.0-14.15~18.04.1
4.18.0-15.16~18.04.1
4.18.0-16.17~18.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "block-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "block-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "block-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "crypto-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "crypto-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "crypto-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "dasd-extra-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "dasd-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fat-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fat-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fat-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fb-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "firewire-core-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "floppy-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fs-core-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fs-core-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fs-core-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fs-secondary-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fs-secondary-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "fs-secondary-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "input-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "input-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "input-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "ipmi-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "ipmi-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "ipmi-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "kernel-image-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "kernel-image-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "kernel-image-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-buildinfo-4.18.0-17-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-buildinfo-4.18.0-17-generic-lpae",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-buildinfo-4.18.0-17-lowlatency",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-buildinfo-4.18.0-17-snapdragon",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-cloud-tools-4.18.0-17-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-cloud-tools-4.18.0-17-lowlatency",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-headers-4.18.0-17",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-headers-4.18.0-17-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-headers-4.18.0-17-generic-lpae",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-headers-4.18.0-17-lowlatency",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-headers-4.18.0-17-snapdragon",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-hwe-cloud-tools-4.18.0-17",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-hwe-tools-4.18.0-17",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-hwe-udebs-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-hwe-udebs-generic-lpae",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-hwe-udebs-snapdragon",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-4.18.0-17-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-4.18.0-17-generic-dbgsym",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-4.18.0-17-generic-lpae",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-4.18.0-17-generic-lpae-dbgsym",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-4.18.0-17-lowlatency",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-4.18.0-17-lowlatency-dbgsym",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-4.18.0-17-snapdragon",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-4.18.0-17-snapdragon-dbgsym",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-unsigned-4.18.0-17-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-unsigned-4.18.0-17-generic-dbgsym",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-unsigned-4.18.0-17-lowlatency",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-image-unsigned-4.18.0-17-lowlatency-dbgsym",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-modules-4.18.0-17-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-modules-4.18.0-17-generic-lpae",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-modules-4.18.0-17-lowlatency",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-modules-4.18.0-17-snapdragon",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-modules-extra-4.18.0-17-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-source-4.18.0",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-tools-4.18.0-17-generic",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-tools-4.18.0-17-generic-lpae",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-tools-4.18.0-17-lowlatency",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "linux-tools-4.18.0-17-snapdragon",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "md-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "md-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "md-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "message-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "message-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "mouse-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "mouse-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "mouse-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "multipath-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "multipath-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "multipath-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nfs-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nfs-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nfs-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-pcmcia-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-shared-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-shared-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-shared-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-usb-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-usb-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "nic-usb-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "parport-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "parport-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "parport-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "pata-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "pcmcia-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "pcmcia-storage-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "plip-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "plip-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "plip-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "ppp-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "ppp-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "ppp-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "sata-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "sata-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "sata-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "scsi-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "scsi-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "scsi-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "serial-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "storage-core-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "storage-core-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "storage-core-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "usb-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "usb-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "usb-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "virtio-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "virtio-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "vlan-modules-4.18.0-17-generic-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "vlan-modules-4.18.0-17-generic-lpae-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        },
        {
            "binary_name": "vlan-modules-4.18.0-17-snapdragon-di",
            "binary_version": "4.18.0-17.18~18.04.1"
        }
    ],
    "availability": "No subscription required"
}