PT-2019-3981 · Linux+2 · Linux Kernel+2

Published

2019-11-06

·

Updated

2021-07-11

·

CVE-2019-18814

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.3.9
Description The issue is related to a use-after-free error in the aa audit rule init() function, located in security/apparmor/audit.c, which can be exploited by a remote attacker to execute arbitrary code. The error occurs when aa label parse() fails in aa audit rule init().
Recommendations For Linux kernel versions prior to 5.3.9, update to version 5.3.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the aa audit rule init() function until a patch is available.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3113
ALT-PU-2019-3136
ALT-PU-2019-3184
ALT-PU-2020-1198
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-1501
ALT-PU-2020-1714
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-04512
CVE-2019-18814
DLA-2323-1
MGASA-2020-0333
OPENSUSE-SU-2021:0532-1
OPENSUSE-SU-2021:0758-1
OPENSUSE-SU-2021:1975-1
OPENSUSE-SU-2021:1977-1
OPENSUSE-SU-2021_0532-1
OPENSUSE-SU-2021_0758-1
OPENSUSE-SU-2021_1975-1
OPENSUSE-SU-2021_1977-1
SUSE-SU-2021:1177-1
SUSE-SU-2021:1211-1
SUSE-SU-2021:1238-1
SUSE-SU-2021:1625-1
SUSE-SU-2021:1975-1
SUSE-SU-2021:1977-1
SUSE-SU-2021_1177-1
SUSE-SU-2021_1211-1
SUSE-SU-2021_1238-1

Affected Products

Alt Linux
Linux Kernel
Suse