Blog | G5 Cyber Security

Linux Kernel Prior to 5.0.8 Vulnerable to Remote Code Execution

Linux kernel’s rds_tcp_kill_sock implementation in net/rds/tcp.c to trigger denial-of-service (DoS) states and to execute code remotely on vulnerable Linux machines. Linux kernel developers issued a patch for the CVE-2019-11815 issue during late-March and fixed the flaw in the Linux kernel 5.0.8 version released on April 17. A similar issue that could lead to arbitrary code execution was also discovered by Google Project Zero’s Jann Horn in December 2016.

Source: https://www.bleepingcomputer.com/news/security/linux-kernel-prior-to-508-vulnerable-to-remote-code-execution/

Exit mobile version