Back

HIGH

kernel: NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c

Published Nov 4, 2019

Description

An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0.

Affected products

Remediation

Red Hat mitigation

While this is a network protocol being affected, the protocol is not available by default. A local process (or user) can trigger the protocol to be used which will then be loaded automatically would then have the vulnerable code loaded and the attack vector opened. To reiterate it is unlikely that most Linux systems will be using this protocol and therefore affected. Most systems do _NOT_ have this protocol used by services. This is an infrequently used module and if you wish to blacklist it, you can follow the steps outlined in https://access.redhat.com/solutions/41278 to blacklist the "rds_tcp" module for the relevant version of Red Hat Enterprise Linux.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 4, 2019
Updated Aug 5, 2024
Reserved Nov 4, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 18, 2019