iproute2 before 5.1.0 has a use-after-free in getnetnsidfrom_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.15.0-2ubuntu1.1", "binary_name": "iproute2" }, { "binary_version": "4.15.0-2ubuntu1.1", "binary_name": "iproute2-dbgsym" }, { "binary_version": "4.15.0-2ubuntu1.1", "binary_name": "iproute2-doc" } ] }