TROYANOSYVIRUS
Retour aux CVEs

CVE-2019-11487

HIGH
7.8

Description

The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.

Details CVE

Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie4/23/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

canonical:ubuntu_linuxdebian:debian_linuxlinux:linux_kernel

Faiblesses (CWE)

CWE-416

References

http://www.openwall.com/lists/oss-security/2019/04/29/1(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/108054(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:2703(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:2741(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2020:0174(af854a3a-2127-422b-91ae-364da2661108)
https://lwn.net/Articles/786044/(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20190517-0005/(af854a3a-2127-422b-91ae-364da2661108)
https://support.f5.com/csp/article/K14255532(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/4069-1/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/4069-2/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/4115-1/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/4118-1/(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/4145-1/(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuApr2021.html(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.