atalkcreate in net/appletalk/ddp.c in the AFAPPLETALK network module in the Linux kernel through 5.3.2 does not enforce CAPNETRAW, which means that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"132617565344710949304546757919875734542",
"175089575801174205916040995873460732102",
"89976506165762883247086184469426210375",
"41063545702728339049824147402492191465"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@6cc03e8aa36c51f3b26a0d21a3c4ce2809c842ac",
"deprecated": false,
"id": "CVE-2019-17054-1ee67e94",
"signature_type": "Line",
"target": {
"file": "net/appletalk/ddp.c"
},
"signature_version": "v1"
},
{
"digest": {
"length": 515.0,
"function_hash": "157316366613327590720450669989278987453"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@6cc03e8aa36c51f3b26a0d21a3c4ce2809c842ac",
"deprecated": false,
"id": "CVE-2019-17054-579c03eb",
"signature_type": "Function",
"target": {
"function": "atalk_create",
"file": "net/appletalk/ddp.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17054.json"