Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11810

Опубликовано: 07 мая 2019
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-free.

A flaw was found in the Linux kernel, prior to version 5.0.7, in drivers/scsi/megaraid/megaraid_sas_base.c, where a NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds(). An attacker can crash the system if they were able to load the megaraid_sas kernel module and groom memory beforehand, leading to a denial of service (DoS), related to a use-after-free.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelOut of support scope
Red Hat Enterprise MRG 2kernel-rtWill not fix
Red Hat Enterprise Linux 6kernelFixedRHSA-2019:273612.09.2019
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2019:204307.08.2019
Red Hat Enterprise Linux 7kernelFixedRHSA-2019:202906.08.2019
Red Hat Enterprise Linux 7kernel-altFixedRHSA-2019:321729.10.2019
Red Hat Enterprise Linux 7.5 Extended Update SupportkernelFixedRHSA-2020:003607.01.2020
Red Hat Enterprise Linux 7.6 Extended Update SupportkernelFixedRHSA-2019:283720.09.2019
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2019:197130.07.2019
Red Hat Enterprise Linux 8kernelFixedRHSA-2019:195930.07.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1709164kernel: a NULL pointer dereference in drivers/scsi/megaraid/megaraid_sas_base.c leading to DoS

EPSS

Процентиль: 80%
0.01451
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-free.

CVSS3: 7.5
nvd
около 6 лет назад

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-free.

CVSS3: 7.5
debian
около 6 лет назад

An issue was discovered in the Linux kernel before 5.0.7. A NULL point ...

CVSS3: 7.5
github
около 3 лет назад

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-free.

oracle-oval
почти 6 лет назад

ELSA-2019-2736: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 80%
0.01451
Низкий

6.2 Medium

CVSS3