7.8

CVE-2019-15538

An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 4.7 < 4.9.191
LinuxLinux Kernel Version >= 4.14 < 4.14.141
LinuxLinux Kernel Version >= 4.19 < 4.19.69
LinuxLinux Kernel Version >= 5.2 < 5.2.11
LinuxLinux Kernel Version5.3 Update-
LinuxLinux Kernel Version5.3 Updaterc1
LinuxLinux Kernel Version5.3 Updaterc2
LinuxLinux Kernel Version5.3 Updaterc3
LinuxLinux Kernel Version5.3 Updaterc4
LinuxLinux Kernel Version5.3 Updaterc5
LinuxLinux Kernel Version5.3 Updaterc6
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version19.04
NetappSolidfire Version-
NetappAff A700s Firmware Version-
   NetappAff A700s Version-
NetappH300s Firmware Version-
   NetappH300s Version-
NetappH500s Firmware Version-
   NetappH500s Version-
NetappH700s Firmware Version-
   NetappH700s Version-
NetappH300e Firmware Version-
   NetappH300e Version-
NetappH500e Firmware Version-
   NetappH500e Version-
NetappH700e Firmware Version-
   NetappH700e Version-
NetappH410s Firmware Version-
   NetappH410s Version-
NetappH410c Firmware Version-
   NetappH410c Version-
NetappH610s Firmware Version-
   NetappH610s Version-
OpensuseLeap Version15.0
OpensuseLeap Version15.1
DebianDebian Linux Version8.0
FedoraprojectFedora Version29
FedoraprojectFedora Version30
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.43% 0.947
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

https://usn.ubuntu.com/4147-1/
Third Party Advisory
https://usn.ubuntu.com/4144-1/
Third Party Advisory