| Vulnerability Name: | CVE-2019-10140 (CCN-165372) |
| Assigned: | 2019-08-15 |
| Published: | 2019-08-15 |
| Updated: | 2023-02-12 |
| Summary: | A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS). |
| CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) 4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)| Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): None | | Scope: | Scope (S): Unchanged
| | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): High | 6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)| Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | | Scope: | Scope (S): Unchanged
| | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): High | 5.5 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) 4.9 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)| Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): None | | Scope: | Scope (S): Unchanged
| | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): High |
|
| CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)| Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Authentication (Au): None | | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Complete | 4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)| Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): None
| | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Complete |
|
| Vulnerability Type: | CWE-476
|
| Vulnerability Consequences: | Denial of Service |
| References: | Source: MITRE Type: CNA CVE-2019-10140
Source: CCN Type: IBM Security Bulletin 1072398 (Spectrum Protect Plus) Linux Kernel vulnerabilities affect IBM Spectrum Protect Plus CVE-2019-10140, CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-13233, CVE-2019-13272, CVE-2019-14283, CVE-2019-14284, CVE-2019-15090, CVE-2019-15807, CVE-2019-15925
Source: secalert@redhat.com Type: Issue Tracking, Third Party Advisory secalert@redhat.com
Source: XF Type: UNKNOWN linux-kernel-cve201910140-dos(165372)
Source: CCN Type: oss-sec Mailing List, Thu, 15 Aug 2019 13:37:57 +1000 CVE-2019-10140 - linux kernel - system panic in overlayfs directory creation
Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com
Source: CCN Type: Linux Kernel Web site The Linux Kernel Archives
|
| Vulnerable Configuration: | Configuration RedHat 1: cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*Configuration RedHat 2: cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*Configuration RedHat 3: cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*Configuration RedHat 4: cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*Configuration RedHat 5: cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*Configuration RedHat 6: cpe:/a:redhat:rhel_extras_rt:7:*:*:*:*:*:*:* Configuration CCN 1: cpe:/o:linux:linux_kernel:3.10:*:*:*:*:*:*:*AND cpe:/a:ibm:spectrum_protect_plus:10.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:spectrum_protect_plus:10.1.1:*:*:*:*:*:*:*OR cpe:/a:ibm:spectrum_protect_plus:10.1.2:*:*:*:*:*:*:*OR cpe:/a:ibm:spectrum_protect_plus:10.1.3:*:*:*:*:*:*:*OR cpe:/a:ibm:spectrum_protect_plus:10.1.4:*:*:*:*:*:*:*
Denotes that component is vulnerable |
| Oval Definitions |
|
| BACK |