Executive Summary

Informations
NameCVE-2019-9857First vendor Publication2019-03-21
VendorCveLast vendor Modification2019-04-09

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score4.9Attack RangeLocal
Cvss Impact Score6.9Attack ComplexityLow
Cvss Expoit Score3.9AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() in fs/notify/inotify/inotify_user.c neglects to call fsnotify_put_mark() with IN_MASK_CREATE after fsnotify_find_mark(), which will cause a memory leak (aka refcount leak). Finally, this will cause a denial of service.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9857

CWE : Common Weakness Enumeration

%idName
100 %CWE-399Resource Management Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Os3224

Sources (Detail)

SourceUrl
BID http://www.securityfocus.com/bid/107527
CONFIRM https://security.netapp.com/advisory/ntap-20190404-0002/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
MISC https://git.kernel.org/pub/scm/linux/kernel/git/jack/linux-fs.git/commit/?h=f...
https://patchwork.kernel.org/patch/10836283/

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
DateInformations
2019-07-02 15:40:37
  • Multiple Updates
2019-06-21 12:10:10
  • Multiple Updates
2019-06-18 12:10:13
  • Multiple Updates
2019-06-15 12:10:55
  • Multiple Updates
2019-05-04 12:09:06
  • Multiple Updates
2019-04-24 12:08:57
  • Multiple Updates
2019-04-09 09:19:06
  • Multiple Updates
2019-04-05 00:19:10
  • Multiple Updates
2019-04-04 17:19:29
  • Multiple Updates
2019-03-29 00:19:23
  • Multiple Updates
2019-03-26 17:19:14
  • Multiple Updates
2019-03-22 17:19:10
  • Multiple Updates
2019-03-21 21:19:24
  • First insertion