Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-15666

Description

An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation.

POC

Reference

- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b805d78d300bcf2c83d6df7da0c818b0fee41427

Github

- https://github.com/Al1ex/LinuxEelvation

- https://github.com/De4dCr0w/Linux-kernel-EoP-exp

- https://github.com/DrewSC13/Linpeas

- https://github.com/HaxorSecInfec/autoroot.sh

- https://github.com/JlSakuya/Linux-Privilege-Escalation-Exploits

- https://github.com/a-roshbaik/Linux-Privilege-Escalation-Exploits

- https://github.com/bsauce/kernel-exploit-factory

- https://github.com/bsauce/kernel-security-learning

- https://github.com/gglessner/Rocky

- https://github.com/go-bi/go-bi-soft

- https://github.com/siddicky/yotjf

- https://github.com/substing/internal_ctf

- https://github.com/vlain1337/auto-lpe