kernel: ppc: unrelated processes being able to read/write to each other's virtual memory
Published Jun 25, 2019
7.0
HIGHCVSS 3.1
EPSS 0.39%
Description
arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected.
Affected products
No data.
Configuration 1
- 18.04
- 18.10
- 19.04
Configuration 2
- < 5.1.15
Configuration 3
- 29
- 30
Configuration 4
- 9.0
- 10.0
Configuration 6
- 8.0
- 8.1
- 8.2
- 8.4
- 8.2
- 8.4
- 8.2
- 8.4
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-80.11.1.el8_0
Fixed · RHSA-2019:2703
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-80.11.1.el8_0 | Fixed | RHSA-2019:2703 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00025.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/24/5 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108884 vdb-entryx_refsource_BIDBroken Link
- https://access.redhat.com/errata/RHSA-2019:2703 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-12817 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1720616 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.15 x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4398 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ca72d88378b2f2444d3ec145dd442d449d3fefbc x_refsource_MISCPatchVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OTLN3KQYEEWWAJYA4BUYYDMWWXCJQNV2/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WSKLL2374YGFQR6LSVCFGTTCRGBTLAWZ/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-12817
- https://seclists.org/bugtraq/2019/Aug/13 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/oss-sec/2019/q2/200
- https://support.f5.com/csp/article/K12876166 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K12876166?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4031-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-12817
- https://www.debian.org/security/2019/dsa-4495 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data