PT-2019-2798 · Linux+5 · Linux Kernel+5

Jann Horn

·

Publicado

2019-06-07

·

Atualizado

2021-05-28

·

CVE-2019-13233

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.1.9
Description The issue is related to a use-after-free condition in the Linux kernel, specifically in the arch/x86/lib/insn-eval.c file. This condition arises due to a race between the modify ldt() function and a #BR exception that occurs for an MPX bounds violation. The vulnerability can potentially be exploited to elevate privileges.
Recommendations For Linux kernel versions prior to 5.1.9, update to version 5.1.9 or later to resolve the issue.

Exploit

Correção

Race Condition

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2116
ALT-PU-2019-2117
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-02751
CESA-2019_3309
CESA-2019_3517
CESA-2020_1016
CVE-2019-13233
DSA-4495-1
OPENSUSE-SU-2019:1757-1
OPENSUSE-SU-2019_1757-1
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_3309
RHSA-2019_3517
RHSA-2020:1016
RHSA-2020:1070
RHSA-2020:2522
RHSA-2020:2851
RHSA-2020_1016
RHSA-2020_1070
SUSE-SU-2019:1854-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2232-1
SUSE-SU-2019:2430-1
SUSE-SU-2019_2232-1
USN-4093-1
USN-4094-1
USN-4117-1
USN-4118-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu