Unrated severityNVD Advisory· Published Jun 18, 2019· Updated Aug 4, 2024
CVE-2019-3896
CVE-2019-3896
Description
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
Affected products
10- osv-coords9 versionspkg:rpm/suse/kernel-bigmem&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/kernel-ec2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/kernel-pae&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/kernel-ppc64&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/kernel-trace&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS
< 3.0.101-108.98.1+ 8 more
- (no CPE)range: < 3.0.101-108.98.1
- (no CPE)range: < 3.0.101-108.98.1
- (no CPE)range: < 3.0.101-108.98.1
- (no CPE)range: < 3.0.101-108.98.1
- (no CPE)range: < 3.0.101-108.98.1
- (no CPE)range: < 3.0.101-108.98.1
- (no CPE)range: < 3.0.101-108.98.1
- (no CPE)range: < 3.0.101-108.98.1
- (no CPE)range: < 3.0.101-108.98.1
- The Linux Foundation/kernelv5Range: 2.6.32
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/108814mitrevdb-entryx_refsource_BID
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- security.netapp.com/advisory/ntap-20190710-0002/mitrex_refsource_CONFIRM
- support.f5.com/csp/article/K04327111mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.