Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #64103

Bug#928989: linux-image-4.19.0-4-amd64: CVE-2019-11815

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#928989: linux-image-4.19.0-4-amd64: CVE-2019-11815
Date 2019-05-14 21:10 +0200
Message-ID <xXKYh-3YU-3@gated-at.bofh.it> (permalink)
References <xXKvf-3zi-5@gated-at.bofh.it> <xXKvf-3zi-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Control: fixed -1 4.19.37-1
Control: found -1 4.9.168-2
Control: found -1 3.16.64-2
Control: severity -1 important

On Tue, 2019-05-14 at 14:37 -0400, Jeff Cliff wrote:
> Package: src:linux
> Version: 4.19.28-2
> Severity: grave
> Tags: security
> Justification: user security hole
> 
> Dear Maintainer,
> 
> An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the
> Linux kernel before 5.0.8. 
> There is a race condition leading to a use-after-free, related to net
> namespace cleanup.
> 
> the security-tracker is tracking this issue but there does not seem
> to be a bug report for it
> 
> https://security-tracker.debian.org/tracker/CVE-2019-11815
> 
> Fixed by: 
> https://git.kernel.org/linus/cb66ddd156203daefb8d71158036b27b0e2caf63
> 
> currently affects: buster/testing, stable
> currently does not affect: sid
[...]

This was already mitigated in older suites, in that we disable auto-
loading of the rds module.  This is therefore only exploitable on
systems that actually use rds.  For that reason, I'm downgrading this
to "important".

Ben.

-- 
Ben Hutchings
I haven't lost my mind; it's backed up on tape somewhere.


Back to linux.debian.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

Bug#928989: linux-image-4.19.0-4-amd64: CVE-2019-11815 Jeff Cliff <jeffrey.cliff@gmail.com> - 2019-05-14 20:40 +0200
  Processed: Re: Bug#928989: linux-image-4.19.0-4-amd64: CVE-2019-11815 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2019-05-14 21:10 +0200
  Bug#928989: linux-image-4.19.0-4-amd64: CVE-2019-11815 Ben Hutchings <ben@decadent.org.uk> - 2019-05-14 21:10 +0200

csiph-web