AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-15239

HIGH · CVSS 7.8 EPSS 0.59%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-20 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Linux.

CVE
CVE-2019-15239
Severity
HIGH
CVSS
7.8
EPSS
0.59%
Linux

Original NVD Description

In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnection and re-connection, a local attacker can trigger multiple use-after-free conditions. This can result in a kernel crash, or potentially in privilege escalation. NOTE: this affects (for example) Linux distributions that use 4.9.x longterm kernels before 4.9.190 or 4.14.x longterm kernels before 4.14.139.

Related CVEs

Other vulnerabilities affecting the same vendor(s)