CVE-2019-17056
Vulnerability Summary
Timeline
Description
llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-3a359798b176.
CVSS Metrics
- v4.0•MEDIUM•Score: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- v3.1•LOW•Score: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 0.57%• Percentile: 46%
Techniques & Countermeasures
- CWE-276•Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
Affected Systems
- debian•linux
< 5.3.7-1 | < 5.3.7-1 | < 5.3.7-1 | < 5.3.7-1
- ubuntu•linux
all | < 4.4.0-168.197 | < 4.15.0-69.78
- ubuntu•linux-aws
< 4.4.0-1058.62 | < 4.4.0-1098.109 | < 4.15.0-1054.56
- ubuntu•linux-aws-fips
< 4.15.0-2018.18 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1054.56~16.04.1
- ubuntu•linux-azure
< 4.15.0-1063.68~14.04.1 | < 4.15.0-1063.68 | < 5.0.0-1025.27~18.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fips
< 4.15.0-2006.7 | all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1025.30 | all
- ubuntu•linux-gcp
< 4.15.0-1049.52 | < 5.0.0-1025.26~18.04.1
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-gcp-fips
all
- ubuntu•linux-gke
all
- ubuntu•linux-gke-4.15
< 4.15.0-1048.51
- ubuntu•linux-gke-5.0
< 5.0.0-1025.26~18.04.1
- ubuntu•linux-hwe
< 4.15.0-69.78~16.04.1 | < 5.0.0-35.38~18.04.1
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1062.69 | < 4.15.0-1050.50
- ubuntu•linux-lts-xenial
< 4.4.0-168.197~14.04.1
- ubuntu•linux-oem
< 4.15.0-1063.72
- ubuntu•linux-oem-osp1
< 5.0.0-1027.31
- ubuntu•linux-oracle
< 4.15.0-1029.32~16.04.1 | < 4.15.0-1029.32
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1125.134 | < 4.15.0-1050.54
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1129.137 | < 4.15.0-1067.74
- linux•linux_kernel
≤ 5.3.2
References (23)
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0edc3f703f7bcaf550774b5d43ab727bcd0fe06b
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3a359798b176183ef09efb7a3dc59abad1cc7104
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6JNEWGIK7QA24OIUUL67QZNJN52NB7T/
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00064.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html
- https://seclists.org/bugtraq/2019/Nov/11
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- https://usn.ubuntu.com/4185-1/
- https://usn.ubuntu.com/4184-1/
- https://usn.ubuntu.com/4186-1/
- https://usn.ubuntu.com/4185-2/
- https://usn.ubuntu.com/4186-2/
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://ubuntu.com/security/CVE-2019-17056
- https://git.kernel.org/linus/3a359798b176183ef09efb7a3dc59abad1cc7104
- https://ubuntu.com/security/notices/USN-4184-1
- https://ubuntu.com/security/notices/USN-4185-1
- https://ubuntu.com/security/notices/USN-4185-2
- https://ubuntu.com/security/notices/USN-4186-1
- https://ubuntu.com/security/notices/USN-4186-2
- https://www.cve.org/CVERecord?id=CVE-2019-17056
- https://security-tracker.debian.org/tracker/CVE-2019-17056