Vulnerability Name:

CVE-2019-3896 (CCN-162709)

Assigned:2019-06-17
Published:2019-06-17
Updated:2023-02-12
Summary:A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.0 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.1 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-416
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2019-3896

Source: CCN
Type: IBM Security Bulletin 964466 (Netezza Host Management)
IBM Netezza Host Management is affected by the vulnerabilities known as Intel Microarchitectural Data Sampling (MDS) and other Kernel vulnerabilities

Source: secalert@redhat.com
Type: Third Party Advisory, VDB Entry
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla - Bug 1694812
CVE-2019-3896 kernel: Double free in lib/idr.c

Source: secalert@redhat.com
Type: Issue Tracking, Third Party Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
linux-kernel-cve20193896-priv-esc(162709)

Source: CCN
Type: Linux Kernel GIT Reporitory
idr: fix top layer handling

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: IBM Security Bulletin 1074536 (QRadar SIEM)
Linux kernel as used by IBM QRadar SIEM is vulnerable to privilege escalation(Publicly disclosed vulnerability) (CVE-2019-3896)

Source: CCN
Type: IBM Security Bulletin 1074042 (Security QRadar Packet Capture)
IBM Security QRadar Packet Capture is vulnerable to Denial of Service (CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-3896)

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:2.6.0:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:qradar_security_information_and_event_manager:7.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20193896
    V
    CVE-2019-3896
    2022-09-02
    oval:org.opensuse.security:def:35294
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:34014
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:30275
    P
    Security update for ruby2.1 (Important)
    2021-12-01
    oval:org.opensuse.security:def:33050
    P
    Security update for the Linux Kernel (Important)
    2021-11-30
    oval:org.opensuse.security:def:31311
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:31290
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:34561
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:33725
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:34549
    P
    Security update for gd (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:34550
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:31251
    P
    Security update for unrar (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:33957
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:30220
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:34475
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:31202
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:36083
    P
    apache2-mod_jk-1.2.40-0.2.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:34431
    P
    Security update for the Linux Kernel (Important)
    2021-05-13
    oval:org.opensuse.security:def:33900
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:33642
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:30067
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:35245
    P
    Security update for the Linux Kernel (Important)
    2021-04-15
    oval:org.opensuse.security:def:34406
    P
    Security update for the Linux Kernel (Important)
    2021-04-13
    oval:org.opensuse.security:def:32894
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:33631
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:33630
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:31146
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:33107
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:31355
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:34645
    P
    Security update for openldap2 (Important)
    2021-03-03
    oval:org.opensuse.security:def:33939
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:28858
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:36042
    P
    systemtap-1.5-0.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:32443
    P
    Security update for xen (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35027
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30426
    P
    Security update for xorg-x11-libs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30540
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29169
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:29620
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32750
    P
    mozilla-xulrunner192 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30757
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34318
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:29887
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29705
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:35404
    P
    Security update for openssh-openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28433
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30991
    P
    Security update for jakarta-commons-fileupload (Important)
    2020-12-01
    oval:org.opensuse.security:def:29981
    P
    Security update for libsndfile (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33195
    P
    libxslt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28717
    P
    Security update for kdebase4-workspace
    2020-12-01
    oval:org.opensuse.security:def:35153
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:29010
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32432
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:34937
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:30382
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:30539
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29152
    P
    Security update for libssh2_org (Important)
    2020-12-01
    oval:org.opensuse.security:def:32656
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31101
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:30625
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:34260
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29851
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:29632
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:35360
    P
    Security update for nagios-nrpe, nagios-nrpe-debuginfo, nagios-nrpe-debugsource, nagios-nrpe-doc, nagios-plugins-nrpe
    2020-12-01
    oval:org.opensuse.security:def:28422
    P
    Security update for wavpack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30904
    P
    Security update for foomatic-filters (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29924
    P
    Security update for Mozilla
    2020-12-01
    oval:org.opensuse.security:def:33156
    P
    libjasper on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28632
    P
    Security update for a2ps
    2020-12-01
    oval:org.opensuse.security:def:35113
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:33262
    P
    stunnel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32431
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:34880
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:30363
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33861
    P
    Security update for jakarta-commons-fileupload (Important)
    2020-12-01
    oval:org.opensuse.security:def:29113
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32031
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32521
    P
    gmime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35186
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31064
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:30551
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:34103
    P
    Security update for MozillaFirefox, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:29213
    P
    Security update for perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29621
    P
    Security update for boost
    2020-12-01
    oval:org.opensuse.security:def:32807
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35333
    P
    Security update for mono-core (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28421
    P
    Security update for wavpack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30847
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34367
    P
    Security update for tftp
    2020-12-01
    oval:org.opensuse.security:def:29837
    P
    Security update for kdelibs3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28501
    P
    Security update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33218
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28774
    P
    Security update for libvirt
    2020-12-01
    oval:org.opensuse.security:def:34781
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:30324
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29064
    P
    Security update for bzip2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31993
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:com.ubuntu.disco:def:201938960000000
    V
    CVE-2019-3896 on Ubuntu 19.04 (disco) - medium.
    2019-06-19
    oval:com.ubuntu.bionic:def:201938960000000
    V
    CVE-2019-3896 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-06-19
    oval:com.ubuntu.xenial:def:201938960000000
    V
    CVE-2019-3896 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-06-19
    oval:com.ubuntu.cosmic:def:201938960000000
    V
    CVE-2019-3896 on Ubuntu 18.10 (cosmic) - medium.
    2019-06-18
    oval:com.redhat.rhsa:def:20191488
    P
    RHSA-2019:1488: kernel security and bug fix update (Important)
    2019-06-17
    BACK
    linux linux kernel 2.6.0
    ibm qradar security information and event manager 7.2