Resource management error in Linux kernel - CVE-2019-13648

 

Resource management error in Linux kernel - CVE-2019-13648

Published: July 26, 2019 / Updated: May 30, 2020


Vulnerability identifier: #VU19387
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13648
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists in the "arch/powerpc/kernel/signal_32.c" and "arch/powerpc/kernel/signal_64.c" files on the PowerPC platform, when hardware transactional memory is disabled. A local authenticated attacker can make a "sigreturn()" system call that sends a signal frame that sends a signal frame that submits malicious input to the targeted system and cause a denial of service condition.


Affected software

Linux kernel
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
Opensuse
Fedora
kernel (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
kernel
kernel-headers
kernel-tools
4769 Developer's Toolkit

How to mitigate CVE-2019-13648

Install update from vendor's website.

Linux kernel - addressed in versions 4.4.187, 4.9.187, 4.19.63, 5.2.5
kernel (Red Hat package) - update to 3.10.0-1062.30.1.el7
kernel - update to 5.2.5-200.fc30
kernel-headers - update to 5.2.5-200.fc30
kernel-tools - update to 5.2.5-200.fc30
4769 Developer's Toolkit - update to 7.3.44

External References

Related Security Bulletins