CVE-2019-3896
published 2019-06-19CVE-2019-3896: A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege…
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.2th percentile
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.41-1 (bookworm) | linux 3.2.41-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | 2.6.0 – 2.6.39.4 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| the_linux_foundation | kernel | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2p8m-h2q6-92v8: A double-free can happen in idr_remove_all() in lib/idr
ghsa_unreviewed·2022-05-24
CVE-2019-3896 [HIGH] CWE-415 GHSA-2p8m-h2q6-92v8: A double-free can happen in idr_remove_all() in lib/idr
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
OSV
CVE-2019-3896: A double-free can happen in idr_remove_all() in lib/idr
osv·2019-06-19·CVSS 7.8
CVE-2019-3896 [HIGH] CVE-2019-3896: A double-free can happen in idr_remove_all() in lib/idr
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
Red Hat
kernel: Double free in lib/idr.c
vendor_redhat·2019-06-17·CVSS 7.0
CVE-2019-3896 [HIGH] CWE-416 kernel: Double free in lib/idr.c
kernel: Double free in lib/idr.c
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
Package: kernel (Red Hat Enterprise Linux 5) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-r
Debian
CVE-2019-3896: linux - A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2....
vendor_debian·2019·CVSS 7.0
CVE-2019-3896 [HIGH] CVE-2019-3896: linux - A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2....
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in 3.2.41-1)
forky: resolved (fixed in 3.2.41-1)
sid: resolved (fixed in 3.2.41-1)
trixie: resolved (fixed in 3.2.41-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/108814https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3896https://security.netapp.com/advisory/ntap-20190710-0002/https://support.f5.com/csp/article/K04327111http://www.securityfocus.com/bid/108814https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3896https://security.netapp.com/advisory/ntap-20190710-0002/https://support.f5.com/csp/article/K04327111
2019-06-19
Published