Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3896

Опубликовано: 17 июн. 2019
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2019:148817.06.2019
Red Hat Enterprise Linux 6.5 Advanced Update SupportkernelFixedRHSA-2019:149017.06.2019
Red Hat Enterprise Linux 6.6 Advanced Update SupportkernelFixedRHSA-2019:148917.06.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416

EPSS

Процентиль: 30%
0.0011
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
около 6 лет назад

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).

CVSS3: 7
nvd
около 6 лет назад

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).

CVSS3: 7
debian
около 6 лет назад

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux ...

CVSS3: 7.8
github
около 3 лет назад

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).

CVSS3: 7.8
fstec
около 6 лет назад

Уязвимость функции idr_remove_all() ядра Linux операционных систем Red Hat Enterprise Linux, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.0011
Низкий

7 High

CVSS3