In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 5.0-rc1 | 5.0-rc1.x |
| linux / linux_kernel | 5.0-rc2 | 5.0-rc2.x |
| linux / linux_kernel | 5.0-rc3 | 5.0-rc3.x |
| linux / linux_kernel | 5.0-rc4 | 5.0-rc4.x |
| linux / linux_kernel | 4.18 | 4.19.18 |
| linux / linux_kernel | 4.20 | 4.20.5 |
| canonical / ubuntu_linux | 18.04 | 18.04.x |
| canonical / ubuntu_linux | 18.10 | 18.10.x |
| opensuse / leap | 15.0 | 15.0.x |