kernel: use-after-free information leak in SMB2_read
Published Sep 4, 2019
4.3
MEDIUMCVSS 3.1
EPSS 1.77%
Description
An issue was discovered in the Linux kernel before 5.0.10. SMB2_read in fs/cifs/smb2pdu.c has a use-after-free. NOTE: this was not fixed correctly in 5.0.10; see the 5.0.11 ChangeLog, which documents a memory leak.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.el8
Fixed · RHSA-2019:3517
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.el8 | Fixed | RHSA-2019:3517 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
As the CIFS module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions: # echo "install cifs /bin/true" >> /etc/modprobe.d/disable-cifs.conf The system will need to be restarted if the CIFS modules are loaded. In most circumstances, the CIFS kernel modules will be unable to be unloaded while any network interfaces are active and the protocol is in use. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.
References (9)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-15920 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1760864 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10 x_refsource_MISCMailing ListVendor Advisory
- https://github.com/torvalds/linux/commit/088aaf17aa79300cab14dbee2569c58cfafd7d6e x_refsource_MISCExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15920
- https://security.netapp.com/advisory/ntap-20191004-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-15920
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html | vendor-advisoryx_refsource_SUSEThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html | vendor-advisoryx_refsource_SUSEThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-15920 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1760864 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10 | x_refsource_MISCMailing ListVendor Advisory | |
| https://github.com/torvalds/linux/commit/088aaf17aa79300cab14dbee2569c58cfafd7d6e | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-15920 | ||
| https://security.netapp.com/advisory/ntap-20191004-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-15920 |
Change history (0)
No recorded changes yet.