CVE-2019-11810: Null Pointer Dereference
A flaw was found in the Linux kernel, prior to version 5.0.7, in drivers/scsi/megaraid/megaraidsasbase.c, where a NULL pointer dereference can occur when megasascreateframepool() fails in megasasalloccmds(). An attacker can crash the system if they were able to load the megaraidsas kernel module and groom memory beforehand, leading to a denial of service (DoS), related to a use-after-free.
Other sources
An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasascreateframepool() fails in megasasalloccmds() in drivers/scsi/megaraid/megaraidsasbase.c. This causes a Denial of Service, related to a use-after-free.
In the Linux kernel before 5.0.7. a NULL pointer dereference can occur when megasascreateframepool() fails in megasasalloccmds() in drivers/scsi/megaraid/megaraidsasbase.c. leading to Denial of Service, related to a use-after-free.
Upstream Patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=bcf3b67d16a4c8ffae0aa79de5853435e683945c
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-754.22.1.el6 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.rt56.1022.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.el7 - Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-115.14.1.el7a - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-862.46.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.35.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.7.1.rt9.153.el8_0 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.7.1.el8_0 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1 - Upgrade
Upgrade
linux kernelto a version that resolves this vulnerability.Fixed in 5.0.7
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-11810?
The severity of CVE-2019-11810 is classified as moderate due to the potential for system crashes.
How do I fix CVE-2019-11810?
To fix CVE-2019-11810, ensure your Linux kernel is updated to version 5.0.7 or later.
Which Linux distributions are affected by CVE-2019-11810?
CVE-2019-11810 affects various distributions including certain versions of Red Hat, Debian, and Ubuntu.
What are the potential impacts of CVE-2019-11810?
The potential impacts of CVE-2019-11810 include denial of service due to unexpected system crashes.
Is CVE-2019-11810 remotely exploitable?
CVE-2019-11810 is not considered remotely exploitable as it requires local access to the affected system.