CVE-2019-9003: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.

In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
  • Linux Linux Kernel: from 4.18, before 4.19.18 (fixed in 4.19.18); from 4.20, before 4.20.5 (fixed in 4.20.5); version 5.0 only
  • Netapp CN1610 Firmware: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Snapprotect: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Opensuse Leap: version 15.0 only

Published 2019-02-22. Last modified 2026-06-17.