Executive Summary

Informations
NameCVE-2019-11487First vendor Publication2019-04-23
VendorCveLast vendor Modification2019-05-17

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score7.2Attack RangeLocal
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score3.9AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11487

CWE : Common Weakness Enumeration

%idName
100 %CWE-416Use After Free

CPE : Common Platform Enumeration

TypeDescriptionCount
Os3282

Sources (Detail)

SourceUrl
BID http://www.securityfocus.com/bid/108054
CONFIRM https://security.netapp.com/advisory/ntap-20190517-0005/
https://support.f5.com/csp/article/K14255532
MISC https://bugs.chromium.org/p/project-zero/issues/detail?id=1752
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15...
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6b...
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=88...
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8f...
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f9...
https://github.com/torvalds/linux/commit/15fab63e1e57be9fdb5eec1bbc5916e9825e...
https://github.com/torvalds/linux/commit/6b3a707736301c2128ca85ce85fb13f60b5e...
https://github.com/torvalds/linux/commit/88b1a17dfc3ed7728316478fae0f5ad508f5...
https://github.com/torvalds/linux/commit/8fde12ca79aff9b5ba951fce1a2641901b8d...
https://github.com/torvalds/linux/commit/f958d7b528b1b40c44cfda5eabe2d82760d8...
https://lwn.net/Articles/786044/
MLIST http://www.openwall.com/lists/oss-security/2019/04/29/1
https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html
https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html
REDHAT https://access.redhat.com/errata/RHSA-2019:2703
https://access.redhat.com/errata/RHSA-2019:2741
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html
UBUNTU https://usn.ubuntu.com/4069-1/
https://usn.ubuntu.com/4069-2/
https://usn.ubuntu.com/4115-1/
https://usn.ubuntu.com/4118-1/
https://usn.ubuntu.com/4145-1/

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
DateInformations
2019-10-02 12:01:24
  • Multiple Updates
2019-09-16 12:01:11
  • Multiple Updates
2019-09-14 12:10:30
  • Multiple Updates
2019-09-12 12:10:54
  • Multiple Updates
2019-09-11 12:03:51
  • Multiple Updates
2019-09-03 12:03:27
  • Multiple Updates
2019-08-28 12:05:31
  • Multiple Updates
2019-08-06 12:03:43
  • Multiple Updates
2019-08-02 12:10:27
  • Multiple Updates
2019-07-24 12:05:05
  • Multiple Updates
2019-07-02 15:40:00
  • Multiple Updates
2019-06-29 12:02:31
  • Multiple Updates
2019-06-21 12:09:49
  • Multiple Updates
2019-06-19 12:10:02
  • Multiple Updates
2019-06-18 12:09:51
  • Multiple Updates
2019-06-15 12:10:33
  • Multiple Updates
2019-05-17 17:19:35
  • Multiple Updates
2019-05-14 12:09:16
  • Multiple Updates
2019-05-03 21:19:26
  • Multiple Updates
2019-05-02 12:09:26
  • Multiple Updates
2019-04-30 21:19:28
  • Multiple Updates
2019-04-30 05:19:23
  • Multiple Updates
2019-04-24 21:19:44
  • Multiple Updates
2019-04-24 05:19:00
  • First insertion