PT-2019-3454 · Linux+5 · Linux Kernel+5

Praveen Pandey

·

Published

2019-07-18

·

Updated

2021-05-28

·

CVE-2019-13648

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.2.1 on the powerpc platform
Description The issue is related to an error in resource management when using the sigreturn() system call. A local user can cause a denial of service, leading to a TM Bad Thing exception and system crash, by sending a crafted signal frame via a sigreturn() system call. This affects the arch/powerpc/kernel/signal 32.c and arch/powerpc/kernel/signal 64.c files.
Recommendations For Linux kernel versions prior to 5.2.1 on the powerpc platform: As a temporary workaround, consider restricting the use of the sigreturn() system call until a patch is available. Avoid using the sigreturn() system call with crafted signal frames to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2339
ALT-PU-2019-2366
ALT-PU-2019-2382
ALT-PU-2019-2401
ALT-PU-2019-2465
ALT-PU-2019-2481
ALT-PU-2019-2488
ALT-PU-2019-2746
ALT-PU-2020-1025
ALT-PU-2020-1070
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-03627
CESA-2019_3517
CESA-2020_1016
CVE-2019-13648
DLA-1885-1
DSA-4495-1
DSA-4497-1
OPENSUSE-SU-2019:1923-1
OPENSUSE-SU-2019:1924-1
OPENSUSE-SU-2019_1923-1
OPENSUSE-SU-2019_1924-1
RHSA-2019:3517
RHSA-2019_3517
RHSA-2020:1016
RHSA-2020:3019
RHSA-2020_1016
SUSE-SU-2019:2068-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2070-1
SUSE-SU-2019:2071-1
SUSE-SU-2019:2072-1
SUSE-SU-2019:2073-1
SUSE-SU-2019:2262-1
SUSE-SU-2019:2263-1
SUSE-SU-2019:2430-1
SUSE-SU-2019:2450-1
USN-4114-1
USN-4115-1
USN-4115-2
USN-4116-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu