CVE-2019-14898
published 2020-05-08CVE-2019-14898: The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause…
PriorityP428high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.44%
35.7th percentile
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| linux | linux_kernel | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_redhat7.8HIGH
vendor_debian7.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: incomplete fix for race condition between mmget_not_zero()/get_task_mm() and core dumping in CVE-2019-11599
vendor_redhat·2019-11-20·CVSS 7.8
CVE-2019-14898 [HIGH] CWE-821 kernel: incomplete fix for race condition between mmget_not_zero()/get_task_mm() and core dumping in CVE-2019-11599
kernel: incomplete fix for race condition between mmget_not_zero()/get_task_mm() and core dumping in CVE-2019-11599
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.
The fix for CVE-2019-11599 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.
Statement: The Red Hat Enterprise Linux 7 kernel versions prior to Red Hat Enterprise Linux 7.7 GA kernel (version 3.10.0-1062 rele
Debian
CVE-2019-14898: linux - The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not com...
vendor_debian·2019·CVSS 7.0
CVE-2019-14898 [HIGH] CVE-2019-14898: linux - The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not com...
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-8qqf-qhmm-w3cm: The fix for CVE-2019-11599, affecting the Linux kernel before 5
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2019-14898 [HIGH] CWE-362 GHSA-8qqf-qhmm-w3cm: The fix for CVE-2019-11599, affecting the Linux kernel before 5
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.
OSV
CVE-2019-14898: The fix for CVE-2019-11599, affecting the Linux kernel before 5
osv·2020-05-08·CVSS 7.0
CVE-2019-14898 [HIGH] CVE-2019-14898: The fix for CVE-2019-11599, affecting the Linux kernel before 5
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.
No detection rules found.
No public exploits indexed.
https://bugs.chromium.org/p/project-zero/issues/detail?id=1790https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14898https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.37https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10https://security.netapp.com/advisory/ntap-20200608-0001/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://bugs.chromium.org/p/project-zero/issues/detail?id=1790https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14898https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.37https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10https://security.netapp.com/advisory/ntap-20200608-0001/https://www.oracle.com/security-alerts/cpuApr2021.html
2020-05-08
Published