CVE-2019-16746: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 12.7% chance of exploitation in the next 30 days.
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 30 only
- Linux Linux Kernel: from 2.6.25, before 3.16.79 (fixed in 3.16.79); from 3.17, before 4.4.197 (fixed in 4.4.197); from 4.5, before 4.9.197 (fixed in 4.9.197); from 4.10, before 4.14.149 (fixed in 4.14.149); from 4.15, before 4.19.79 (fixed in 4.19.79); from 4.20, before 5.3.6 (fixed in 5.3.6)
- Opensuse Leap: version 15.1 only
Published 2019-09-24. Last modified 2026-06-17.