CVE Database
/

CVE-2019-11599

Back to search

CVE-2019-11599

Published: Apr 29, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c, mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

46781
exploit
x_refsource_EXPLOIT-DB
108113
vdb-entry
x_refsource_BID
DSA-4465
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2019:1716
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1757
vendor-advisory
x_refsource_SUSE
USN-4069-1
vendor-advisory
x_refsource_UBUNTU
USN-4069-2
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:2043
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2029
vendor-advisory
x_refsource_REDHAT
USN-4095-1
vendor-advisory
x_refsource_UBUNTU
USN-4115-1
vendor-advisory
x_refsource_UBUNTU
USN-4118-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:3309
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3517
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0100
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0103
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0179
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0543
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now