CVE-2019-18198: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.

Affected products

  • Canonical Ubuntu Linux: version 19.10 only
  • Linux Linux Kernel: from 5.3, before 5.3.4 (fixed in 5.3.4)

Published 2019-10-18. Last modified 2026-06-17.