CVE-2019-20422: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel before 5.3.4, fib6_rule_lookup in net/ipv6/ip6_fib.c mishandles the RT6_LOOKUP_F_DST_NOREF flag in a reference-count decision, leading to (for example) a crash that was identified by syzkaller, aka CID-7b09c2d052db.
Affected products
- Linux Linux Kernel: before 5.3.4 (fixed in 5.3.4)
Published 2020-01-27. Last modified 2026-06-17.