CVE-2019-11811: Use After Free
A flaw was found in the Linux kernel's implementation of IPMI (remote baseband access). An attacker, with local access to read /proc/ioports, may be able to create a use-after-free condition when the kernel module is unloaded which may result in privilege escalation.
Other sources
A flaw was found in the Linux kernels implementation of IPMI (remote baseband access) where an attacker with local access to read /proc/ioports may be able to create a use-after-free condition when the kernel module is unloaded. The use after-free condition may result in privilege escalation. Investigation is ongoing.
Upstream Patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=401e7e88d4ef80188ffa07095ac00456f901b8c4
— Red Hat
An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmisi module is removed, related to drivers/char/ipmi/ipmisiintf.c, drivers/char/ipmi/ipmisimemio.c, and drivers/char/ipmi/ipmisiportio.c.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-11811?
CVE-2019-11811 is a vulnerability in the Linux kernel that allows a use-after-free attack when attempting to read /proc/ioports after the ipmi_si module is removed.
What is the severity of CVE-2019-11811?
CVE-2019-11811 has a severity level of high.
Which software versions are affected by CVE-2019-11811?
The affected software versions include kernel-rt 3.10.0-957.27.2.rt56.940.el7, kernel 3.10.0-957.27.2.el7, kernel-alt 4.14.0-115.26.1.el7a, and more.
How can I fix CVE-2019-11811?
To fix CVE-2019-11811, users should update their Linux kernel to a version that includes the necessary patch.
Where can I find more information about CVE-2019-11811?
More information about CVE-2019-11811 can be found on the CVE and NVD websites, as well as Red Hat's Bugzilla and Errata pages.