CVE-2019-3901

CVSS v3.1 4.7 (Medium)
47% Progress
CVSS v2.0 1.9 (Low)
19% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 11
Advisories 4

A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before perf_event_alloc() actually attaches to it, allowing an attacker to bypass the ptrace_may_access() check and the perf_event_exit_task(current) call that is performed in install_exec_creds() during privileged execve() calls. This issue affects kernel versions before 4.8.

Weaknesses
CWE-667
Improper Locking
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2019-04-22 16:29:01
(5 years ago)
Updated Date
2023-02-12 23:38:57
(19 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Linux Kernel prior 4.8 version cpe:2.3:o:linux:linux_kernel < 4.8

Configuration #2

AND
    CPE23 From Up To
OR  
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0

Configuration #3

AND
    CPE23 From Up To
OR  
  Netapp Active Iq Unified Manager for Vmware Vsphere from 9.5 version cpe:2.3:a:netapp:active_iq_unified_manager_for_vmware_vsphere >= 9.5
OR  
  Running on/with
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
OR  
  Running on/with
  Netapp Snapprotect cpe:2.3:a:netapp:snapprotect:-
OR  
  Running on/with
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-
OR  
  Running on/with
  Netapp Storage Replication Adapter for Clustered Data Ontap For Vmware Vsphere from 7.2 version cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap_for_vmware_vsphere >= 7.2
OR  
  Running on/with
  Netapp Vasa Provider for Clustered Data Ontap from 7.2 version cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap >= 7.2
OR  
  Running on/with
  Netapp Virtual Storage Console for Vmware Vsphere from 7.2 version cpe:2.3:a:netapp:virtual_storage_console_for_vmware_vsphere >= 7.2

Configuration #4

AND
    CPE23 From Up To
OR  
  Netapp Cn1610 Firmware cpe:2.3:o:netapp:cn1610_firmware:-
OR  
  Running on/with
  Netapp Cn1610 cpe:2.3:h:netapp:cn1610:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...