Resource management error in Linux kernel - CVE-2019-15538

 

Resource management error in Linux kernel - CVE-2019-15538

Published: August 28, 2019


Vulnerability identifier: #VU20420
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15538
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to buggy implementation of quotas in "xfs_setattr_nonsize" in the "fs/xfs/xfs_iops.c" file. A local attacker can send specially crafted requests to the affected system and perform denial of service attack.

Note: This vulnerability can be exploited remotely, if XFS filesystem is exported for instance via NFS.


Affected software

Linux kernel
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Fedora
kernel-alt (Red Hat package)
kernel
kernel-headers
kernel-tools

How to mitigate CVE-2019-15538

Install updates from vendor's website.

Linux kernel - update to 5.2.10
kernel-alt (Red Hat package) - update to 4.14.0-115.21.2.el7a
kernel - addressed in versions 5.2.11-100.fc29, 5.2.11-200.fc30
kernel-headers - addressed in versions 5.2.11-100.fc29, 5.2.11-200.fc30
kernel-tools - addressed in versions 5.2.11-100.fc29, 5.2.11-200.fc30

External References

Related Security Bulletins