Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13233

Опубликовано: 04 июл. 2019
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

A vulnerability was found in the arch/x86/lib/insn-eval.c function in the Linux kernel. An attacker could corrupt the memory due to a flaw in use-after-free access to an LDT entry caused by a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise MRG 2kernel-rtOut of support scope
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2020:107031.03.2020
Red Hat Enterprise Linux 7kernelFixedRHSA-2020:101631.03.2020
Red Hat Enterprise Linux 7.6 Extended Update SupportkernelFixedRHSA-2020:285107.07.2020
Red Hat Enterprise Linux 7.7 Extended Update SupportkernelFixedRHSA-2020:252211.06.2020
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2019:330905.11.2019
Red Hat Enterprise Linux 8kernelFixedRHSA-2019:351705.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1727756kernel: use-after-free in arch/x86/lib/insn-eval.c

EPSS

Процентиль: 22%
0.00068
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
почти 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

CVSS3: 7
nvd
почти 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

CVSS3: 7
debian
почти 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is ...

suse-cvrf
почти 6 лет назад

Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP1)

CVSS3: 7
github
около 3 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

EPSS

Процентиль: 22%
0.00068
Низкий

5.1 Medium

CVSS3