A vulnerability was found in ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel, does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768. Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0614e2b73768b502fc32a75349823356d98aae2c https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0edc3f703f7bcaf550774b5d43ab727bcd0fe06b
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1758240]
kernel-5.3.6-100.fc29, kernel-headers-5.3.6-100.fc29, kernel-tools-5.3.6-100.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report.
Red Hat Enterprise Linux does not ship a kernel with support for the AF_AX25 socket type and therefore Red Hat Enterprise Linux is not affected.