CVE-2019-9857
Dashboard / Vulnerabilities / CVE-2019-9857
CVE-2019-9857
Summary:
Details: In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() in fs/notify/inotify/inotify_user.c neglects to call fsnotify_put_mark() with IN_MASK_CREATE after fsnotify_find_mark(), which will cause a memory leak (aka refcount leak). Finally, this will cause a denial of service.
References: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXLZ2V2ES37A3J7DMK4MZYIWV2LEZFLM/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PPH3B7FJOMWD5JWUPZKB6T44KNT4PX2L/, http://www.securityfocus.com/bid/107527, https://security.netapp.com/advisory/ntap-20190404-0002/, https://git.kernel.org/pub/scm/linux/kernel/git/jack/linux-fs.git/commit/?h=fsnotify&id=62c9d2674b31d4c8a674bee86b7edc6da2803aea, https://patchwork.kernel.org/patch/10836283/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
