PT-2019-2808 · Linux+5 · Linux Kernel+5

Published

2019-04-11

·

Updated

2023-02-24

·

CVE-2019-11487

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.1-rc5
Description The issue is related to a reference count overflow in the Linux kernel, specifically with the page-> refcount, which can lead to use-after-free issues. This can occur when there is approximately 140 GiB of RAM and is associated with files such as fs/fuse/dev.c, fs/pipe.c, and others. The exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information. It can be triggered by FUSE requests.
Recommendations For Linux kernel versions prior to 5.1-rc5, update to version 5.1-rc5 or later to resolve the issue. As a temporary workaround, consider restricting the amount of RAM available to prevent the reference count overflow. Additionally, restricting access to FUSE requests may help minimize the risk of exploitation until a patch is applied.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1762
ALT-PU-2019-1765
ALT-PU-2019-1767
BDU:2019-02763
CESA-2019_2703
CESA-2019_2741
CESA-2020_0839
CESA-2020_4182
CVE-2019-11487
DLA-1919-1
DLA-1919-2
OPENSUSE-SU-2019:1571-1
OPENSUSE-SU-2019:1579-1
OPENSUSE-SU-2019_1570-1
OPENSUSE-SU-2019_1571-1
OPENSUSE-SU-2019_1579-1
RHSA-2019:2703
RHSA-2019:2741
RHSA-2019_2703
RHSA-2019_2741
RHSA-2020:0174
RHSA-2020:0834
RHSA-2020:0839
RHSA-2020:2851
RHSA-2020:3230
RHSA-2020:3266
RHSA-2020:4182
RHSA-2020_0834
RHSA-2020_0839
RHSA-2020_4182
SUSE-SU-2019:1529-1
SUSE-SU-2019:1530-1
SUSE-SU-2019:1535-1
SUSE-SU-2019:1536-1
SUSE-SU-2019:1550-1
SUSE-SU-2019:1581-1
SUSE-SU-2019:1588-1
SUSE-SU-2019:1668-1
SUSE-SU-2019:1671-1
SUSE-SU-2019:1674-1
SUSE-SU-2019:1767-1
SUSE-SU-2019:1768-1
SUSE-SU-2019:1823-1
SUSE-SU-2019:1823-2
SUSE-SU-2019:1852-1
SUSE-SU-2019:1870-1
SUSE-SU-2019:2430-1
SUSE-SU-2019:2821-1
USN-4069-1
USN-4069-2
USN-4115-1
USN-4115-2
USN-4118-1
USN-4145-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu