CVE-2019-9003: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
- Linux Linux Kernel: from 4.18, before 4.19.18 (fixed in 4.19.18); from 4.20, before 4.20.5 (fixed in 4.20.5); version 5.0 only
- Netapp CN1610 Firmware: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Snapprotect: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Opensuse Leap: version 15.0 only
Published 2019-02-22. Last modified 2026-06-17.