High severity7.8NVD Advisory· Published Apr 1, 2019· Updated Jun 17, 2026
CVE-2019-8956
CVE-2019-8956
Description
In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <4.19.21 || >=4.20,<4.20.8
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- git.kernel.org/cgit/linux/kernel/git/stable/linux-stable.git/commit/nvdMailing ListPatchVendor Advisory
- cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.21nvdRelease NotesVendor Advisory
- cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.20.8nvdRelease NotesVendor Advisory
- support.f5.com/csp/article/K12671141nvdThird Party Advisory
- usn.ubuntu.com/3930-1/nvdThird Party Advisory
- usn.ubuntu.com/3930-2/nvdThird Party Advisory
- secuniaresearch.flexerasoftware.com/secunia_research/2019-5/nvdBroken Link
News mentions
0No linked articles in our index yet.