---
id: CVE-2019-25160
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netlabel: fix out-of-bounds memory accesses

  There are two array out-of-bounds memory accesses, one in
  cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk()
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netlabel: fix out-of-bounds memory accesses

  There are two array out-of-bounds memory accesses, one in
  cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk().  Bot…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.19, < 3.16.66'
  - 'linux_kernel >= 3.17.0, < 3.18.137'
  - 'linux_kernel >= 3.19.0, < 4.4.177'
  - 'linux_kernel >= 4.5.0, < 4.9.163'
  - 'linux_kernel >= 4.10.0, < 4.14.106'
  - 'linux_kernel >= 4.15.0, < 4.19.28'
  - 'linux_kernel >= 4.20.0, < 4.20.15'
patched:
  - linux_kernel 4.20.15
published: '2024-02-26'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25160'
references:
  - url: 'https://git.kernel.org/stable/c/1c973f9c7cc2b3caae93192fdc8ecb3f0b4ac000'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5578de4834fe0f2a34fedc7374be691443396d1f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/97bc3683c24999ee621d847c9348c75d2fe86272'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c61d01faa5550e06794dcf86125ccd325bfad950'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dc18101f95fa6e815f426316b8b9a5cee28a334e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e3713abc4248aa6bcc11173d754c418b02a62cbb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fbf9578919d6c91100ec63acf2cba641383f6c78'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fcfe700acdc1c72eab231300e82b962bac2b2b2c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1c973f9c7cc2b3caae93192fdc8ecb3f0b4ac000'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/5578de4834fe0f2a34fedc7374be691443396d1f'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/97bc3683c24999ee621d847c9348c75d2fe86272'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/c61d01faa5550e06794dcf86125ccd325bfad950'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/dc18101f95fa6e815f426316b8b9a5cee28a334e'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e3713abc4248aa6bcc11173d754c418b02a62cbb'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/fbf9578919d6c91100ec63acf2cba641383f6c78'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/fcfe700acdc1c72eab231300e82b962bac2b2b2c'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00745
epssPercentile: 0.5335
ingestedAt: '2026-08-04T10:39:38.046Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netlabel: fix out-of-bounds memory accesses

There are two array out-of-bounds memory accesses, one in
cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk().  Both
errors are embarassingly simple, and the fixes are straightforward.

As a FYI for anyone backporting this patch to kernels prior to v4.8,
you'll want to apply the netlbl_bitmap_walk() patch to
cipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before
Linux v4.8.

## Affected

- `linux_kernel >= 2.6.19, < 3.16.66`
- `linux_kernel >= 3.17.0, < 3.18.137`
- `linux_kernel >= 3.19.0, < 4.4.177`
- `linux_kernel >= 4.5.0, < 4.9.163`
- `linux_kernel >= 4.10.0, < 4.14.106`
- `linux_kernel >= 4.15.0, < 4.19.28`
- `linux_kernel >= 4.20.0, < 4.20.15`

## Remediation

Upgrade past the affected range:

- `linux_kernel 4.20.15`
