PT-2019-5306 · Linux+2 · Linux Kernel+2
Publicado
2019-04-19
·
Atualizado
2023-02-12
·
CVE-2019-14898
CVSS v3.1
7.0
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.0.10
Description
The issue is related to a flaw in the Linux kernel that allows a local user to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts. This is achieved by triggering a race condition with
mmget not zero or get task mm calls. The vulnerability is caused by synchronization errors when using a shared resource.Recommendations
For Linux kernel versions prior to 5.0.10, update to version 5.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.
Exploit
Correção
DoS
Race Condition
Improper Locking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Linux Kernel
Red Hat