CVE-2019-10140
published 2019-08-15CVE-2019-10140: A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service…
PriorityP418medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.32%
24.1th percentile
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| linux | linux_kernel | <= 3.10 | — |
| opensource | kernel | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.4MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: overlayfs: NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c
vendor_redhat·2019-08-15·CVSS 5.5
CVE-2019-10140 [MEDIUM] CWE-476 kernel: overlayfs: NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c
kernel: overlayfs: NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
A vulnerability was found in Linux kernel's implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kern
Debian
CVE-2019-10140: linux - A vulnerability was found in Linux kernel's, versions up to 3.10, implementation...
vendor_debian·2019·CVSS 5.5
CVE-2019-10140 [MEDIUM] CVE-2019-10140: linux - A vulnerability was found in Linux kernel's, versions up to 3.10, implementation...
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-cqfm-vfh2-jprp: A vulnerability was found in Linux kernel's, versions up to 3
ghsa_unreviewed·2022-05-24
CVE-2019-10140 [MEDIUM] CWE-476 GHSA-cqfm-vfh2-jprp: A vulnerability was found in Linux kernel's, versions up to 3
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
OSV
mariadb-10.1 vulnerabilities
osv·2019-06-05·CVSS 4.4
CVE-2019-2614 mariadb-10.1 vulnerabilities
mariadb-10.1 vulnerabilities
USN-3957-1 fixed multiple vulnerabilities in MySQL. This update provides the
corresponding fixes for CVE-2019-2614 and CVE-2019-2627 in MariaDB 10.1.
Ubuntu 18.04 LTS has been updated to MariaDB 10.1.40.
In addition to security fixes, the updated package contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://mariadb.com/kb/en/library/mariadb-10140-changelog/
https://mariadb.com/kb/en/library/mariadb-10140-release-notes/
Original advisory details:
Multiple security issues were discovered in MySQL and this update includes
a new upstream MySQL version to fix these issues.
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 18.10, and Ubuntu 19.04 have
been updated to MySQL 5.7.26.
In addition to se
No detection rules found.
No public exploits indexed.
2019-08-15
Published