PT-2019-2798 · Linux+5 · Linux Kernel+5

Jann Horn

·

Published

2019-06-07

·

Updated

2021-05-28

·

CVE-2019-13233

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.1.9
Description The issue is related to a use-after-free condition in the Linux kernel, specifically in the arch/x86/lib/insn-eval.c file. This condition arises due to a race between the modify ldt() function and a #BR exception that occurs for an MPX bounds violation. The vulnerability can potentially be exploited to elevate privileges.
Recommendations For Linux kernel versions prior to 5.1.9, update to version 5.1.9 or later to resolve the issue.

Exploit

Fix

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2116
ALT-PU-2019-2117
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-02751
CESA-2019_3309
CESA-2019_3517
CESA-2020_1016
CVE-2019-13233
DSA-4495-1
OPENSUSE-SU-2019:1757-1
OPENSUSE-SU-2019_1757-1
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_3309
RHSA-2019_3517
RHSA-2020:1016
RHSA-2020:1070
RHSA-2020:2522
RHSA-2020:2851
RHSA-2020_1016
RHSA-2020_1070
SUSE-SU-2019:1854-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2232-1
SUSE-SU-2019:2430-1
SUSE-SU-2019_2232-1
USN-4093-1
USN-4094-1
USN-4117-1
USN-4118-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu