[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2019-1281 --- kernel perf

ID: oval:org.secpod.oval:def:1601048Date: (C)2019-09-27   (M)2024-04-17
Class: PATCHFamily: unix




A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two code lines were swapped.An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.

Platform:
Amazon Linux AMI
Product:
kernel
perf
Reference:
ALAS-2019-1281
CVE-2019-15538
CVE-2019-15902
CVE    2
CVE-2019-15902
CVE-2019-15538
CPE    134
cpe:/o:linux:linux_kernel:4.9.18
cpe:/o:linux:linux_kernel:4.9.19
cpe:/o:linux:linux_kernel:4.9.16
cpe:/o:linux:linux_kernel:4.9.17
...

© SecPod Technologies