PT-2019-5306 · Linux+2 · Linux Kernel+2

Publicado

2019-04-19

·

Atualizado

2023-02-12

·

CVE-2019-14898

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.0.10
Description The issue is related to a flaw in the Linux kernel that allows a local user to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts. This is achieved by triggering a race condition with mmget not zero or get task mm calls. The vulnerability is caused by synchronization errors when using a shared resource.
Recommendations For Linux kernel versions prior to 5.0.10, update to version 5.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.

Exploit

Correção

DoS

Race Condition

Improper Locking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02253
CESA-2020_0328
CESA-2020_0339
CESA-2020_0374
CESA-2020_0375
CVE-2019-14898
RHSA-2020:0328
RHSA-2020:0339
RHSA-2020:0374
RHSA-2020:0375
RHSA-2020_0328
RHSA-2020_0339
RHSA-2020_0374
RHSA-2020_0375

Produtos afetados

Centos
Linux Kernel
Red Hat