CVE-2019-11487
published 2019-04-23CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.71%
49.9th percentile
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.19.37-1 (bookworm) | linux 4.19.37-1 (bookworm) |
| linux | linux_kernel | < 4.4.216 | 4.4.216 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.19.37-1 | 4.19.37-1 |
| linux | linux_kernel | >= 0 < 4.19.37-1 | 4.19.37-1 |
| linux | linux_kernel | >= 0 < 4.19.37-1 | 4.19.37-1 |
| linux | linux_kernel | >= 0 < 4.19.37-1 | 4.19.37-1 |
| linux | linux_kernel | >= 0 < 4.4.0-165.193 | 4.4.0-165.193 |
| linux | linux_kernel | >= 0 < 4.15.0-62.69 | 4.15.0-62.69 |
| linux | linux_kernel | >= 0 < 4.15.0-60.67 | 4.15.0-60.67 |
| linux | linux_kernel | >= 4.10 < 4.14.116 | 4.14.116 |
| linux | linux_kernel | >= 4.15 < 4.19.39 | 4.19.39 |
| linux | linux_kernel | >= 4.20 < 5.0.12 | 5.0.12 |
| linux | linux_kernel | >= 4.5 < 4.9.181 | 4.9.181 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-10-01·CVSS 7.8
CVE-2016-10905 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the GFS2 file system in
the Linux kernel. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2016-10905)
It was discovered that the IPv6 implementation in the Linux kernel did not
properly validate socket options in some situations. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-18509)
It was discovered that the USB gadget Midi driver in the Linux kernel
contained a double-free vulnerability when handling certain error
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-20961)
Ubuntu
Linux kernel regression
vendor_ubuntu·2019-09-11·CVSS 4.6
[MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: USN 4115-1 introduced a regression in the Linux kernel.
USN 4115-1 fixed vulnerabilities in the Linux 4.15 kernel for Ubuntu
18.04 LTS and Ubuntu 16.04 LTS. Unfortunately, as part of the update,
a regression was introduced that caused a kernel crash when handling
fragmented packets in some situations. This update addresses the issue.
We apologize for the inconvenience.
Original advisory details:
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
service (system crash). (CVE-2018-19985)
Zhipeng Xie discovered that an infinite loop could triggered in the CFS
Linux kernel proc
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of serv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-09-02·CVSS 4.6
CVE-2018-19985 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
service (system crash). (CVE-2018-19985)
Zhipeng Xie discovered that an infinite loop could be triggered in the CFS
Linux kernel process scheduler. A local attacker could possibly use this to
cause a denial of service. (CVE-2018-20784)
It was discovered that the Intel Wi-Fi device driver in the Linux kernel did
not properly validate certain Tunneled Direct Link Setup (TDLS). A
physically proximate attacker could use this to cause a denial of service
(Wi-Fi disconnec
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-08-01·CVSS 7.8
CVE-2019-11487 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4069-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu 18.04 LTS.
It was discovered that an integer overflow existed in the Linux kernel when
reference counting pages, leading to potential use-after-free issues. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-11487)
Jann Horn discovered that a race condition existed in the Linux kernel when
performing core dumps. A local attacker could use this to cause a denial of
service (system crash) or expose sensitive information. (
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-07-23·CVSS 7.8
CVE-2019-11487 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that an integer overflow existed in the Linux kernel when
reference counting pages, leading to potential use-after-free issues. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-11487)
Jann Horn discovered that a race condition existed in the Linux kernel when
performing core dumps. A local attacker could use this to cause a denial of
service (system crash) or expose sensitive information. (CVE-2019-11599)
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information
Red Hat
kernel: Count overflow in FUSE request leading to use-after-free issues.
vendor_redhat·2019-04-22·CVSS 7.8
CVE-2019-11487 [HIGH] CWE-416 kernel: Count overflow in FUSE request leading to use-after-free issues.
kernel: Count overflow in FUSE request leading to use-after-free issues.
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
A flaw was found in the Linux kernel's implementation of the FUSE filesystem, where it allows a page reference counter overflow. If a page reference counter overflows into a negative value, it can be placed back into the "free" list for reuse by other applications. This flaw allows a local attacker who can manipulate memory page reference counters to cause memory corruption and possi
Debian
CVE-2019-11487: linux - The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow,...
vendor_debian·2019·CVSS 7.8
CVE-2019-11487 [HIGH] CVE-2019-11487: linux - The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow,...
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
Scope: local
bookworm: resolved (fixed in 4.19.37-1)
bullseye: resolved (fixed in 4.19.37-1)
forky: resolved (fixed in 4.19.37-1)
sid: resolved (fixed in 4.19.37-1)
trixie: resolved (fixed in 4.19.37-1)
GHSA
GHSA-vrxc-79fp-6683: The Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2019-11487 [HIGH] CWE-416 GHSA-vrxc-79fp-6683: The Linux kernel before 5
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-10-01·CVSS 7.8
CVE-2016-10905 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a race condition existed in the GFS2 file system in
the Linux kernel. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2016-10905)
It was discovered that the IPv6 implementation in the Linux kernel did not
properly validate socket options in some situations. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-18509)
It was discovered that the USB gadget Midi driver in the Linux kernel
contained a double-free vulnerability when handling certain error
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-20961)
It was discovered that th
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression
osv·2019-09-11·CVSS 4.6
[MEDIUM] linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression
USN 4115-1 fixed vulnerabilities in the Linux 4.15 kernel for Ubuntu
18.04 LTS and Ubuntu 16.04 LTS. Unfortunately, as part of the update,
a regression was introduced that caused a kernel crash when handling
fragmented packets in some situations. This update addresses the issue.
We apologize for the inconvenience.
Original advisory details:
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
service (system crash). (CVE-2018-19985)
Zhipeng Xie discovered that an infinite loop could tr
OSV
linux, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 vulnerabilities
osv·2019-09-02·CVSS 4.6
CVE-2018-19985 [MEDIUM] linux, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 vulnerabilities
linux, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 vulnerabilities
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
service (system crash). (CVE-2018-19985)
Zhipeng Xie discovered that an infinite loop could be triggered in the CFS
Linux kernel process scheduler. A local attacker could possibly use this to
cause a denial of service. (CVE-2018-20784)
It was discovered that the Intel Wi-Fi device driver in the Linux kernel did
not properly validate certain Tunneled Direct Link Setup (TDLS). A
physically proximate attacker could use this to cause a denial of service
(Wi-Fi
OSV
linux-aws vulnerabilities
osv·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] linux-aws vulnerabilities
linux-aws vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13096, CVE-2018-13097, CVE-2018-13098,
CVE-2018-1309
OSV
linux-hwe vulnerabilities
osv·2019-08-01·CVSS 7.8
[HIGH] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-4069-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu 18.04 LTS.
It was discovered that an integer overflow existed in the Linux kernel when
reference counting pages, leading to potential use-after-free issues. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-11487)
Jann Horn discovered that a race condition existed in the Linux kernel when
performing core dumps. A local attacker could use this to cause a denial of
service (system crash) or expose sensitive information. (CVE-2019-11599)
It was discovered that the ext4 file system implementation in the
OSV
CVE-2019-11487: The Linux kernel before 5
osv·2019-04-23·CVSS 7.8
CVE-2019-11487 [HIGH] CVE-2019-11487: The Linux kernel before 5
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11487 kernel: Count overflow in FUSE request leading to use-after-free issues. [fedora-all]
bugzilla·2019-04-25·CVSS 7.8
CVE-2019-11487 [HIGH] CVE-2019-11487 kernel: Count overflow in FUSE request leading to use-after-free issues. [fedora-all]
CVE-2019-11487 kernel: Count overflow in FUSE request leading to use-after-free issues. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2019-11487 kernel: Count overflow in FUSE request leading to use-after-free issues.
bugzilla·2019-04-25·CVSS 7.8
CVE-2019-11487 [HIGH] CVE-2019-11487 kernel: Count overflow in FUSE request leading to use-after-free issues.
CVE-2019-11487 kernel: Count overflow in FUSE request leading to use-after-free issues.
A flaw was found in the linux kernel's implementation of the FUSE filesystem, which allows for a page reference counter overflow. If a page reference counter overflows into a negative value it can be put back into the "free" list for re-use by other applications.
A local attacker who is able to manipulate memory page reference counters can abuse this situation to allow for memory corruption and possibly privilege escalation by triggering a Use After Free condition.
The current attack requires the system to have approximately 140 GiB of RAM for this attack to be carried out. It may be possible that the attack can be carried out with lesser memory requirements.
Reporter information:
https://bugs.chro
arXiv
Programmable System Call Security with eBPF
arxiv_fulltext·2023-02-20
Programmable System Call Security with eBPF
Programmable System Call Security with eBPF
Jinghao Jia^1, YiFei Zhu^2, Dan Williams^3, Andrea Arcangeli^4, Claudio Canella^5, Hubertus Franke^6,
Tobin Feldman-Fitzthum^6, Dimitrios Skarlatos^7, Daniel Gruss^8, Tianyin Xu^1
^1University of Illinois at Urbana-Champaign, Urbana, IL, USA
^2Google, Inc., Sunnyvale, CA, USA
^3Virginia Tech, Blacksburg, VA, USA
^4Red Hat, Inc., New York, NY, USA
^5Amazon Web Services, Graz, Austria
^6IBM Research, Yorktown Heights, NY, USA
^7Carnegie Mellon University, Pittsburgh, PA, USA
^8Graz University of Technology, Graz, Austria
## Abstract
System call filtering is a widely used security mechanism
for protecting a shared OS kernel
against untrusted user applications.
However, existing system call filtering techniques either are
too expensive du
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.htmlhttp://www.openwall.com/lists/oss-security/2019/04/29/1http://www.securityfocus.com/bid/108054https://access.redhat.com/errata/RHSA-2019:2703https://access.redhat.com/errata/RHSA-2019:2741https://access.redhat.com/errata/RHSA-2020:0174https://bugs.chromium.org/p/project-zero/issues/detail?id=1752https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15fab63e1e57be9fdb5eec1bbc5916e9825e9acbhttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6b3a707736301c2128ca85ce85fb13f60b5e350ahttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=88b1a17dfc3ed7728316478fae0f5ad508f50397https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8fde12ca79aff9b5ba951fce1a2641901b8d8e64https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f958d7b528b1b40c44cfda5eabe2d82760d868c3https://github.com/torvalds/linux/commit/15fab63e1e57be9fdb5eec1bbc5916e9825e9acbhttps://github.com/torvalds/linux/commit/6b3a707736301c2128ca85ce85fb13f60b5e350ahttps://github.com/torvalds/linux/commit/88b1a17dfc3ed7728316478fae0f5ad508f50397https://github.com/torvalds/linux/commit/8fde12ca79aff9b5ba951fce1a2641901b8d8e64https://github.com/torvalds/linux/commit/f958d7b528b1b40c44cfda5eabe2d82760d868c3https://lists.debian.org/debian-lts-announce/2019/09/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2019/09/msg00015.htmlhttps://lwn.net/Articles/786044/https://security.netapp.com/advisory/ntap-20190517-0005/https://support.f5.com/csp/article/K14255532https://usn.ubuntu.com/4069-1/https://usn.ubuntu.com/4069-2/https://usn.ubuntu.com/4115-1/https://usn.ubuntu.com/4118-1/https://usn.ubuntu.com/4145-1/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.htmlhttp://www.openwall.com/lists/oss-security/2019/04/29/1http://www.securityfocus.com/bid/108054https://access.redhat.com/errata/RHSA-2019:2703https://access.redhat.com/errata/RHSA-2019:2741https://access.redhat.com/errata/RHSA-2020:0174https://bugs.chromium.org/p/project-zero/issues/detail?id=1752https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15fab63e1e57be9fdb5eec1bbc5916e9825e9acbhttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6b3a707736301c2128ca85ce85fb13f60b5e350ahttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=88b1a17dfc3ed7728316478fae0f5ad508f50397https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8fde12ca79aff9b5ba951fce1a2641901b8d8e64https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f958d7b528b1b40c44cfda5eabe2d82760d868c3https://github.com/torvalds/linux/commit/15fab63e1e57be9fdb5eec1bbc5916e9825e9acbhttps://github.com/torvalds/linux/commit/6b3a707736301c2128ca85ce85fb13f60b5e350ahttps://github.com/torvalds/linux/commit/88b1a17dfc3ed7728316478fae0f5ad508f50397https://github.com/torvalds/linux/commit/8fde12ca79aff9b5ba951fce1a2641901b8d8e64https://github.com/torvalds/linux/commit/f958d7b528b1b40c44cfda5eabe2d82760d868c3https://lists.debian.org/debian-lts-announce/2019/09/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2019/09/msg00015.htmlhttps://lwn.net/Articles/786044/https://security.netapp.com/advisory/ntap-20190517-0005/https://support.f5.com/csp/article/K14255532https://usn.ubuntu.com/4069-1/https://usn.ubuntu.com/4069-2/https://usn.ubuntu.com/4115-1/https://usn.ubuntu.com/4118-1/https://usn.ubuntu.com/4145-1/https://www.oracle.com/security-alerts/cpuApr2021.html
2019-04-23
Published