Use After Free Affecting perf package, versions <0:4.18.0-80.1.2.el8_0
Threat Intelligence
EPSS
0.98% (84th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL8-PERF-4362237
- published 26 Jul 2021
- disclosed 16 Jan 2019
Introduced: 16 Jan 2019
CVE-2019-9003 Open this link in a new tabHow to fix?
Upgrade RHEL:8
perf
to version 0:4.18.0-80.1.2.el8_0 or higher.
This issue was patched in RHSA-2019:1167
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream perf
package and not the perf
package as distributed by RHEL
.
See How to fix?
for RHEL:8
relevant fixed versions and status.
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.
References
- http://www.securityfocus.com/bid/107145
- https://security.netapp.com/advisory/ntap-20190327-0002/
- https://access.redhat.com/security/cve/CVE-2019-9003
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=77f8269606bf95fcb232ee86f6da80886f1dfae8
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.20.5
- https://github.com/torvalds/linux/commit/77f8269606bf95fcb232ee86f6da80886f1dfae8
- https://access.redhat.com/errata/RHSA-2019:1167
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00037.html
- https://usn.ubuntu.com/3930-1/
- https://usn.ubuntu.com/3930-2/
CVSS Scores
version 3.1