Bug#928989: linux-image-4.19.0-4-amd64: CVE-2019-11815

2019-05-14 Thread Ben Hutchings
Control: fixed -1 4.19.37-1 Control: found -1 4.9.168-2 Control: found -1 3.16.64-2 Control: severity -1 important On Tue, 2019-05-14 at 14:37 -0400, Jeff Cliff wrote: > Package: src:linux > Version: 4.19.28-2 > Severity: grave > Tags: security > Justification: user security hole > > Dear Maintai

Bug#928989: linux-image-4.19.0-4-amd64: CVE-2019-11815

2019-05-14 Thread Jeff Cliff
Package: src:linux Version: 4.19.28-2 Severity: grave Tags: security Justification: user security hole Dear Maintainer, An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace