CVE-2019-12817: High severity Canonical Ubuntu Linux vulnerability
A flaw was found in the way the Linux kernel's memory subsystem on certain 64-bit PowerPC with the hash page table MMU handled memory above 512TB. A local, unprivileged user could use this flaw to escalate their privileges on the system.
Upstream commit that introduced this issue: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f384796c40dc
Upstream fix: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ca72d88378b2f2444d3ec145dd442d449d3fefbc
Other sources
arch/powerpc/mm/mmucontextbook3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12817?
CVE-2019-12817 has a high severity rating due to the potential for local privilege escalation.
How do I fix CVE-2019-12817?
To fix CVE-2019-12817, update the Linux kernel to versions 4.18.0-24.25, 5.0.0-19.20, or higher.
What systems are affected by CVE-2019-12817?
CVE-2019-12817 affects certain 64-bit PowerPC systems running specific versions of the Linux kernel.
Can a remote attacker exploit CVE-2019-12817?
No, CVE-2019-12817 can only be exploited by a local, unprivileged user.
Are there existing patches for CVE-2019-12817?
Yes, patches for CVE-2019-12817 are included in the recommended kernel updates for affected systems.