CVE-2019-8912: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Linux Linux Kernel: from 4.10, before 4.14.103 (fixed in 4.14.103); from 4.19, before 4.19.25 (fixed in 4.19.25); from 4.20, before 4.20.12 (fixed in 4.20.12); version 5.0 only
  • Opensuse Leap: version 15.0 only
  • Red Hat Enterprise Linux: version 7.0 only

Published 2019-02-18. Last modified 2026-06-17.