cbcvebase.
CVE-2019-11190
published 2019-04-12

CVE-2019-11190: The Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_creds() is called too late in…

PriorityP420medium4.7CVSS 3.0
AVLACHPRLUINSUCHINAN
EPSS
0.48%
38.5th percentile
The Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_creds() is called too late in load_elf_binary() in fs/binfmt_elf.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat.

Affected

8 ranges
VendorProductVersion rangeFixed in
apparmorapparmor>= 0 < 2.10.95-0ubuntu2.112.10.95-0ubuntu2.11
debianlinux< linux 4.8.5-1 (bookworm)linux 4.8.5-1 (bookworm)
linuxlinux_kernel< 4.84.8
linuxlinux_kernel>= 0 < 4.8.5-14.8.5-1
linuxlinux_kernel>= 0 < 4.8.5-14.8.5-1
linuxlinux_kernel>= 0 < 4.8.5-14.8.5-1
linuxlinux_kernel>= 0 < 4.8.5-14.8.5-1
linuxlinux_kernel>= 0 < 4.4.0-150.1764.4.0-150.176

CVSS provenance

nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.