CVE-2019-17133: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 6.7% chance of exploitation in the next 30 days.

In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: from 2.6.32, before 3.16.77 (fixed in 3.16.77); from 3.17, before 4.4.198 (fixed in 4.4.198); from 4.5, before 4.9.198 (fixed in 4.9.198); from 4.10, before 4.14.151 (fixed in 4.14.151); from 4.15, before 4.19.81 (fixed in 4.19.81); from 4.20, before 5.3.8 (fixed in 5.3.8)
  • Opensuse Leap: version 15.1 only

Published 2019-10-04. Last modified 2026-06-17.