Vulnerability Name:

CVE-2019-19241 (CCN-173106)

Assigned:2019-12-16
Published:2019-12-16
Updated:2020-08-24
Summary:In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709. This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an attacker can bypass intended restrictions on adding an IPv4 address to the loopback interface. This occurs because IORING_OP_SENDMSG operations, although requested in the context of an unprivileged user, are sometimes performed by a kernel worker thread without considering that context.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.0 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.0 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2019-19241

Source: MISC
Type: Mailing List, Third Party Advisory
https://bugs.chromium.org/p/project-zero/issues/detail?id=1975

Source: CCN
Type: Google Security Research Issue 1975
Linux: privilege escalation via io_uring offload of sendmsg() onto kernel thread with kernel creds

Source: MISC
Type: Mailing List, Vendor Advisory
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.2

Source: XF
Type: UNKNOWN
linux-kernel-cve201919241-priv-esc(173106)

Source: MISC
Type: Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=181e448d8709e517c9c7b523fcd209f24eb38ca7

Source: MISC
Type: Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d69e07793f891524c6bbf1e75b9ae69db4450953

Source: CCN
Type: Packet Storm Security [12-16-2019]
Linux sendmsg() Privilege Escalation

Source: CONFIRM
Type: UNKNOWN
https://security.netapp.com/advisory/ntap-20200103-0001/

Source: UBUNTU
Type: UNKNOWN
USN-4284-1

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [12-16-2019]

Source: CCN
Type: IBM Security Bulletin 6116992 (Spectrum Protect Plus)
Multiple vulnerabilities in Linux Kernel affect IBM Spectrum Protect Plus

Source: CCN
Type: Linux Kernel Web site
Linux Kernel

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version < 5.4.2)

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:5.3:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:spectrum_protect_plus:10.1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201919241
    V
    CVE-2019-19241
    2023-06-22
    oval:org.opensuse.security:def:8029
    P
    kernel-docs-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:8090
    P
    reiserfs-kmp-default-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7539
    P
    kernel-64kb-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:685
    P
    Security update for bind (Important)
    2022-08-09
    oval:org.opensuse.security:def:665
    P
    Security update for samba (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:3448
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3453
    P
    clamav-0.101.3-1.19 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3567
    P
    libXtst6-1.2.2-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3398
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:1400
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important) (in QA)
    2022-06-27
    oval:org.opensuse.security:def:94590
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95197
    P
    kernel-default-extra-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95028
    P
    kernel-docs-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95078
    P
    reiserfs-kmp-default-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2960
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95083
    P
    kernel-azure-5.14.21-150400.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:89
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:1792
    P
    Security update for MozillaThunderbird (Important)
    2021-12-22
    oval:org.opensuse.security:def:49126
    P
    Security update for runc (Moderate)
    2021-12-14
    oval:org.opensuse.security:def:66952
    P
    Security update for strongswan (Important)
    2021-10-19
    oval:org.opensuse.security:def:94182
    P
    (Important)
    2021-08-17
    oval:org.opensuse.security:def:63125
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2036
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63102
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2013
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:101039
    P
    perl-Convert-ASN1-0.27-1.6.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71848
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1930
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100851
    P
    grub2-2.04-20.4 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62107
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100865
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100891
    P
    libXv-devel-1.0.11-1.23 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1018
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101277
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72738
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100895
    P
    libXxf86vm-devel-1.1.4-1.23 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63019
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:94178
    P
    (Important)
    2021-07-14
    oval:org.opensuse.security:def:66860
    P
    Security update for ffmpeg (Important)
    2021-07-14
    oval:org.opensuse.security:def:1465
    P
    Security update for postgresql13 (Moderate)
    2021-07-11
    oval:org.opensuse.security:def:69672
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:66817
    P
    Security update for pam_radius (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:73643
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:93741
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:66759
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:70207
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:70203
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:69777
    P
    Security update for subversion (Important)
    2021-02-10
    oval:org.opensuse.security:def:70308
    P
    Security update for python (Important)
    2021-02-09
    oval:org.opensuse.security:def:66851
    P
    Security update for go1.14 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:66725
    P
    Security update for libzypp, zypper (Moderate)
    2021-01-13
    oval:org.opensuse.security:def:70173
    P
    Security update for openssh (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:66421
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-11
    oval:org.opensuse.security:def:71515
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1870
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100454
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61774
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2025
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107561
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63088
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117119
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107120
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63623
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116678
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107705
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117220
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72678
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1999
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107517
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62959
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117075
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2534
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94326
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63114
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107557
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94138
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117115
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:70068
    P
    libQt5OpenGLExtensions-devel-static on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49852
    P
    osc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73508
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73390
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:49841
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70102
    P
    libmp3lame-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50179
    P
    bogofilter-common on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73542
    P
    kernel-azure on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49072
    P
    cpp7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73424
    P
    libgypsy-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49906
    P
    kernel-azure on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66329
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:49787
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73525
    P
    perl-Net-Libproxy on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50233
    P
    kernel-default-extra on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73112
    P
    kernel-default on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:72994
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:com.ubuntu.disco:def:2019192410000000
    V
    CVE-2019-19241 on Ubuntu 19.04 (disco) - medium.
    2019-12-17
    oval:com.ubuntu.bionic:def:2019192410000000
    V
    CVE-2019-19241 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-12-17
    oval:com.ubuntu.xenial:def:2019192410000000
    V
    CVE-2019-19241 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-12-17
    BACK
    linux linux kernel *
    linux linux kernel 5.3
    ibm spectrum protect plus 10.1.0