UBUNTU-CVE-2019-15794
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-15794
UBUNTU-CVE-2019-15794
Summary:
Details: Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.
References: https://ubuntu.com/security/CVE-2019-15794, https://ubuntu.com/security/notices/USN-4208-1, https://ubuntu.com/security/notices/USN-4209-1, https://www.cve.org/CVERecord?id=CVE-2019-15794
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
