Back

MEDIUM

kernel: lack of check for mmap minimum address in expand_downwards in mm/mmap.c leads to NULL pointer dereferences exploit on non-SMAP platforms

Published Mar 5, 2019

Description

In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.

Affected products

Remediation

Red Hat mitigation

Enabling selinux prevents the public exploit from working correctly.

References (31)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Mar 5, 2019
Updated Aug 4, 2024
Reserved Feb 27, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Feb 27, 2019
Bugzilla 1686136

ENISA EUVD

Assigner mitre
Published Mar 5, 2019
Updated Aug 4, 2024

GitHub

No data