CVE-2019-8956: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
  • Linux Linux Kernel: from 4.17, before 4.19.21 (fixed in 4.19.21); from 4.20, before 4.20.8 (fixed in 4.20.8)

Published 2019-04-01. Last modified 2026-06-17.