Vulnerability Description
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c, mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.16.12, < 3.16.66 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00014.htmlThird Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00025.htmlThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/152663/Linux-Missing-Lockdown.htmlExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-SlackwarThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/04/29/1Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/29/2Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/30/1Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108113Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2029Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2043Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3309Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3517Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2020:0100Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2020:0103Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2020:0179Third Party AdvisoryVDB Entry
FAQ
What is CVE-2019-11599?
CVE-2019-11599 is a vulnerability with a CVSS score of 7.0 (HIGH). The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sens...
How severe is CVE-2019-11599?
CVE-2019-11599 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11599?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.