FlawAtlas
Search the atlas
UBUNTU-CVE-2019-9162 High

UBUNTU-CVE-2019-9162

In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.

Exploit probability Not scored
Published February 25, 2019
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS linux-azure

23 explicit affected versions

Ubuntu:18.04:LTS linux-gcp-edge

4 explicit affected versions

Ubuntu:18.04:LTS linux-hwe

4 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3930-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2019-9162

In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.

View original source

05 / REFERENCES

Further evidence