CVE-2019-2054
published 2019-05-08CVE-2019-2054: In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.63%
46.2th percentile
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.8.5-1 (bookworm) | linux 4.8.5-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.8.5-1 | 4.8.5-1 |
| linux | linux_kernel | >= 0 < 4.8.5-1 | 4.8.5-1 |
| linux | linux_kernel | >= 0 < 4.8.5-1 | 4.8.5-1 |
| linux | linux_kernel | >= 0 < 4.8.5-1 | 4.8.5-1 |
| linux | linux_kernel | >= 0 < 4.4.0-157.185 | 4.4.0-157.185 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qgfr-27qf-f323: In the seccomp implementation prior to kernel version 4
ghsa_unreviewed·2022-05-24
CVE-2019-2054 [HIGH] GHSA-qgfr-27qf-f323: In the seccomp implementation prior to kernel version 4
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2019-08-13·CVSS 6.8
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-4095-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.
Eli Biham and Lior Neumann discovered that the Bluetooth implementation in
the Linux kernel did not properly validate elliptic curve parameters during
Diffie-Hellman key exchange in some situations. An attacker could use this
to expose sensitive information. (CVE-2018-5383)
It was discovered that a heap buffer overflow existed in the Marvell
Wireless LAN device driver for the Linux kernel. An attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2019-10126)
Andrei Vlad Lutas and
OSV
linux, linux-aws, linux-kvm, linux-raspi2 vulnerabilities
osv·2019-07-25·CVSS 8.1
CVE-2018-20836 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2 vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2 vulnerabilities
It was discovered that a race condition existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel. A local attacker could possibly
use this to cause a denial of service (system crash) or execute arbitrary
code. (CVE-2018-20836)
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)
It was discovered that the Bluetooth Human Interface Device Protocol (HIDP)
implementation in the Linux kernel did not properly verify strings were
NULL terminated in certain situations. A local attacker could use this to
expose sensitive information (kernel mem
OSV
CVE-2019-2054: In the seccomp implementation prior to kernel version 4
osv·2019-05-08·CVSS 7.8
CVE-2019-2054 [HIGH] CVE-2019-2054: In the seccomp implementation prior to kernel version 4
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2019-08-13·CVSS 6.8
CVE-2018-5383 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4095-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.
Eli Biham and Lior Neumann discovered that the Bluetooth implementation in
the Linux kernel did not properly validate elliptic curve parameters during
Diffie-Hellman key exchange in some situations. An attacker could use this
to expose sensitive information. (CVE-2018-5383)
It was discovered that a heap buffer overflow existed in the Marvell
Wireless LAN device driver for the Linux kernel. An attacker could use this
to cause a denial of service (system crash) or po
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-07-25·CVSS 8.1
CVE-2018-20836 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel. A local attacker could possibly
use this to cause a denial of service (system crash) or execute arbitrary
code. (CVE-2018-20836)
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)
It was discovered that the Bluetooth Human Interface Device Protocol (HIDP)
implementation in the Linux kernel did not properly verify strings were
NULL terminated in certain situations. A local attacker could use this
Red Hat
kernel: seccompass mechanism bypass
vendor_redhat·2019-05-01·CVSS 7.8
CVE-2019-2054 [HIGH] CWE-305 kernel: seccompass mechanism bypass
kernel: seccompass mechanism bypass
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499
A flaw was found in the Linux kernel's seccomp implementation which contained a method to bypass seccomp syscall filtering policies that allowed ptrace. This could allow an attacker with code execution privileges within the sandbox to use ptrace to execute systemcalls that would be filtered by the policy.
Statement: Red Hat has considers this CVE as with a 'Moderate' severity due specific condition
Android
CVE-2019-2054: seccomp
vendor_android·2019-05-01·CVSS 7.8
CVE-2019-2054 [HIGH] CVE-2019-2054: seccomp
Android Security Bulletin 2019-05-01
CVE: CVE-2019-2054
Severity: MEDIUM
Type: EoP
Component: seccomp
References: A-119769499*
Debian
CVE-2019-2054: linux - In the seccomp implementation prior to kernel version 4.8, there is a possible s...
vendor_debian·2019·CVSS 7.8
CVE-2019-2054 [HIGH] CVE-2019-2054: linux - In the seccomp implementation prior to kernel version 4.8, there is a possible s...
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499
Scope: local
bookworm: resolved (fixed in 4.8.5-1)
bullseye: resolved (fixed in 4.8.5-1)
forky: resolved (fixed in 4.8.5-1)
sid: resolved (fixed in 4.8.5-1)
trixie: resolved (fixed in 4.8.5-1)
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttps://source.android.com/security/bulletin/2019-05-01https://usn.ubuntu.com/4076-1/https://usn.ubuntu.com/4095-2/http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttps://source.android.com/security/bulletin/2019-05-01https://usn.ubuntu.com/4076-1/https://usn.ubuntu.com/4095-2/
2019-05-08
Published