CVE detail
CVE-2019-17054 — CVE-2019-17054
Published 2019-10-01 · Modified 2026-06-17 · Vendor linux · Product linux_kernel · Source nvd
LOW
severity
CVSS-derived band
0.0051
EPSS probability
exploitation probability, 30d
41.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References