CVE-2019-20054

MEDIUM

Linux Kernel < 5.0.6 - NULL Pointer Dereference in drop_sysctl_table

Title source: llm
STIX 2.1

Description

In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links, aka CID-23da9588037e.

References (6)

Core 6

Scores

CVSS v3 5.5
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (13)
linux/linux_kernel < 5.0.6
netapp/8300_firmware
netapp/8700_firmware
netapp/a400_firmware
netapp/active_iq_unified_manager
netapp/cloud_backup
netapp/data_availability_services
netapp/e-series_santricity_os_controller 11.0 - 11.70.2
netapp/fas\/aff_baseboard_management_controller
netapp/h610s_firmware
... and 3 more
Published Dec 28, 2019
Tracked Since Feb 18, 2026