CVE-2019-3896: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).

Affected products

  • Linux Linux Kernel: from 2.6.0, up to and including 2.6.39.4
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.5 only; version 6.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2019-06-19. Last modified 2026-06-17.