PT-2019-2821 · Linux+5 · Linux Kernel+5

Published

2019-04-19

·

Updated

2024-02-15

·

CVE-2019-11599

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.0.10
Description The issue is caused by errors in synchronization when using a shared resource in the Linux kernel's coredump implementation. This allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget not zero or get task mm calls. The affected files include fs/userfaultfd.c, mm/mmap.c, fs/proc/task mmu.c, and drivers/infiniband/core/uverbs main.c.
Recommendations For Linux kernel versions prior to 5.0.10, update to version 5.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the coredump functionality until a patch is available. Avoid triggering race conditions with mmget not zero or get task mm calls in the affected API endpoints, such as those related to fs/userfaultfd.c, mm/mmap.c, fs/proc/task mmu.c, and drivers/infiniband/core/uverbs main.c, until the issue is resolved.

Exploit

Fix

DoS

Race Condition

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1762
ALT-PU-2019-1767
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-02778
CESA-2019_2029
CESA-2019_3309
CESA-2019_3517
CVE-2019-11599
DLA-1799-1
DLA-1799-2
DLA-1824-1
DSA-4465-1
MGASA-2019-0170
MGASA-2019-0171
MGASA-2019-0172
OPENSUSE-SU-2019:1716-1
OPENSUSE-SU-2019:1757-1
OPENSUSE-SU-2019_1716-1
OPENSUSE-SU-2019_1757-1
RHSA-2019:2029
RHSA-2019:2043
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_2029
RHSA-2019_2043
RHSA-2019_3309
RHSA-2019_3517
RHSA-2020:0100
RHSA-2020:0103
RHSA-2020:0179
RHSA-2020:0543
SUSE-SU-2019:1823-1
SUSE-SU-2019:1823-2
SUSE-SU-2019:1829-1
SUSE-SU-2019:1851-1
SUSE-SU-2019:1852-1
SUSE-SU-2019:1854-1
SUSE-SU-2019:1855-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2430-1
SUSE-SU-2019:2450-1
USN-4069-1
USN-4069-2
USN-4095-1
USN-4115-1
USN-4115-2
USN-4118-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu