CVE-2019-12614: Null Pointer Dereference
A flaw was found in the way Linux kernel's Dynamic Logical Partitioning (DLPAR) functionality on PowerPC systems handled low memory conditions on device discovery. An attacker who can change the LPAR configuration and incur low memory conditions at the same time could use this flaw to crash the system.
Other sources
An issue was discovered in dlparparseccproperty in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).
Reference: https://lkml.org/lkml/2019/6/3/526
Upstream commit: https://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux.git/commit/?id=efa9ace68e487ddd29c2b4d6dd23242158f1f607
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-115.21.2.el7a - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
linux kernel (PowerPC pseries dlpar.c)to a version that resolves this vulnerability.Fixed in 5.1.6Patch efa9ace68e487ddd29c2b4d6dd23242158f1f607 - Compensating control
Because the mitigation is either not available or does not meet the Red Hat Product Security criteria, reduce risk by limiting who can change LPAR configuration and by preventing attackers from being able to simultaneously induce low-memory conditions during device discovery on PowerPC DLPAR systems.
Event History
Parent advisories
This vulnerability appears in the following advisories.