Wind River Support Network

HomeDefectsLIN8-10772
Fixed

LIN8-10772 : Security Advisory - linux - CVE-2019-11190

Created: Apr 14, 2019    Updated: Aug 21, 2019
Resolved Date: Jun 13, 2019
Found In Version: unknown
Fix Version: 8.0.0.31
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Kernel

Description

The Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_creds() is called too late in load_elf_binary() in fs/binfmt_elf.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-11190 User=admin}

CVEs


Live chat
Online