kernel: denial of service in in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
Published Aug 25, 2019
7.5
HIGHCVSS 3.1
EPSS 3.92%
Description
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.
Affected products
No data.
Configuration 1
- ≥ 4.7 · < 4.9.191
- ≥ 4.14 · < 4.14.141
- ≥ 4.19 · < 4.19.69
- ≥ 5.2 · < 5.2.11
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
Configuration 2
- 16.04
- 18.04
- 19.04
Configuration 3
- n/a
- n/a
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 15
- 8.0
Configuration 16
- 29
- 30
No data.
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.21.2.el7a
Fixed · RHSA-2020:2104
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
Kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.21.2.el7a | Fixed | RHSA-2020:2104 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | Kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 3.92% (0.03916) | 90.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.92% (0.03916) | 88.92th | v5 (v2026.06.15) |
| Dec 28, 2025 | 16.43% (0.16428) | 94.66th | v4 (v2025.03.14) |
| Dec 27, 2025 | 13.46% (0.13455) | 94.01th | v4 (v2025.03.14) |
| Nov 21, 2025 | 16.43% (0.16428) | 94.61th | v4 (v2025.03.14) |
| Nov 18, 2025 | 20.54% (0.20545) | 95.16th | v4 (v2025.03.14) |
| Oct 28, 2025 | 16.43% (0.16428) | 94.58th | v4 (v2025.03.14) |
| Oct 27, 2025 | 13.46% (0.13455) | 93.94th | v4 (v2025.03.14) |
| Oct 1, 2025 | 16.43% (0.16428) | 94.67th | v4 (v2025.03.14) |
| Mar 30, 2025 | 13.46% (0.13455) | 93.59th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.34% (0.08336) | 86.87th | v4 (v2025.03.14) |
| Mar 17, 2025 | 13.46% (0.13455) | 93.66th | v4 (v2025.03.14) |
| Dec 17, 2024 | 1.20% (0.01202) | 84.92th | v3 (v2023.03.01) |
| Dec 19, 2023 | 1.80% (0.01801) | 86.77th | v3 (v2023.03.01) |
| Nov 8, 2023 | 2.55% (0.02549) | 89.03th | v3 (v2023.03.01) |
| Sep 3, 2023 | 1.34% (0.01340) | 84.42th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.24% (0.01236) | 83.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.44% (0.23437) | 94.77th | v2 (v2022.01.01) |
| Feb 3, 2022 | 12.48% (0.12481) | 88.86th | v1 |
| Jan 6, 2022 | 12.48% (0.12481) | 88.73th | v1 |
| Jan 5, 2022 | 3.08% (0.03080) | 81.80th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.08% (0.03080) | 0.00th | v1 |
References (18)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-15538 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1746777 Issue Tracking
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee x_refsource_MISCMailing ListPatchVendor Advisory
- https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/ vendor-advisoryx_refsource_FEDORA
- https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/ x_refsource_MISC
- https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2019-15538
- https://security.netapp.com/advisory/ntap-20191004-0001/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K32592426?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4144-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4147-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-15538
Change history (0)
No recorded changes yet.