imPC@ndo IT

Tracker / CVE-2019-15538

CVE-2019-15538

High 7.5

An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
linux linux_kernel
linux linux_kernel · 4.14 → 4.14.141
linux linux_kernel · 4.19 → 4.19.69
linux linux_kernel · 4.7 → 4.9.191
linux linux_kernel · 5.2 → 5.2.11
netapp aff_a700s_firmware
netapp data_availability_services
netapp h300e_firmware
netapp h300s_firmware
netapp h410c_firmware
netapp h410s_firmware
netapp h500e_firmware
netapp h500s_firmware
netapp h610s_firmware
netapp h700e_firmware
netapp h700s_firmware
netapp hci_management_node
netapp solidfire
opensuse leap

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References