CERT-In Vulnerability Note
CIVN-2019-0190
Denial of Service Vulnerability in Linux Kernel
Original Issue Date:December 04, 2019
Severity Rating: MEDIUM
Software Affected
- Linux kernel version5.3.11
Overview
A vulnerability has been reported in Linux kernel which could allow a local attacker to cause denial of service conditions on the target system.
Description
This vulnerability exists in the rwsem_down_write_slowpath of the file "kernel/locking/rwsem.c" of the component btrfs Image Mount Handler in Linux Kernel. A local attacker could exploit this vulnerability by mounting a crafted btrfs image twice leading to use-after-free error.
Successful exploitation of this vulnerability could allow the attacker to cause denial of service conditions on the affected system.
Workaround
- Use restricted environments and restricted shells
- Permit access to trusted individuals only
Vendor Information
Kernel.org
http://www.kernel.org
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19318
References
Kernel.org
http://www.kernel.org
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19318
Symantec
https://www.symantec.com/security-center/vulnerabilities/writeup/111006?om_rssid=sr-advisories
CVE Name
CVE-2019-19318
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|