@@ -192,3 +192,8 @@ CVE_STATUS[CVE-2025-68195] = "fixed-version: Fixed from 6.18"
# Fix https://git.kernel.org/stable/c/b4b64fda4d30a83a7f00e92a0c8a1d47699609f3
# Backport https://git.kernel.org/stable/c/75c5d9bce072abbbc09b701a49869ac23c34a906
CVE_STATUS[CVE-2025-71145] = "cpe-stable-backport: Fixed from v6.18.3"
+
+# Triaged August 2026 - no upstream fix, Ubuntu fix deferred
+# https://ubuntu.com/security/CVE-2019-14899
+CVE_STATUS[CVE-2019-14899] = "unpatched: Consequence of the default weak host \
+model, no upstream fix"
A network-adjacent attacker can send packets addressed to a host's VPN tunnel address over the physical interface. Because Linux uses the weak host model by default, the host replies, which lets the attacker infer the tunnel address, confirm active connections and eventually inject into the tunneled TCP stream. No upstream kernel fix exists. Ubuntu has the fix deferred since 2019-12-13, Debian does not track it against the kernel, and Red Hat scopes it to openvpn: https://ubuntu.com/security/CVE-2019-14899 https://security-tracker.debian.org/tracker/CVE-2019-14899 Record it unpatched so it stays visible rather than excluded. CC: Paul Barker <paul@pbarker.dev> AI-Generated: Uses Claude (claude-opus-5) Signed-off-by: Junjie Cao <junjie.cao@linux.dev> --- v4: - use the review's comment and status wording; drop the mitigation discussion v3: https://lore.kernel.org/openembedded-core/20260812072842.1176341-1-junjie.cao@linux.dev/ meta/recipes-kernel/linux/cve-exclusion.inc | 5 +++++ 1 file changed, 5 insertions(+)