CVE-2019-15538
Vulnerability Summary
Timeline
Description
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v2.0•HIGH•Score: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 16.43%• Percentile: 95%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- canonical•ubuntu_linux
16.04 | 18.04 | 19.04
- debian•debian_linux
8.0
- fedoraproject•fedora
29 | 30
- linux•linux_kernel
≥ 4.7, < 4.9.191 | ≥ 4.14, < 4.14.141 | ≥ 4.19, < 4.19.69 | ≥ 5.2, < 5.2.11 | 5.3 | 5.3:rc1 | 5.3:rc2 | 5.3:rc3 | 5.3:rc4 | 5.3:rc5 | 5.3:rc6
- netapp•aff_a700s
na
- netapp•data_availability_services
na
- netapp•h300e_firmware
na
- netapp•h300s_firmware
na
- netapp•h410c_firmware
na
- netapp•h410s_firmware
na
- netapp•h500e_firmware
na
- netapp•h500s_firmware
na
- netapp•h610s_firmware
na
- netapp•h700e_firmware
na
- netapp•h700s_firmware
na
- netapp•hci_management_node
na
- netapp•solidfire
na
- opensuse•leap
15.0 | 15.1
References (14)
- https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/
- https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local
- https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/
- https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html
- https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html
- https://usn.ubuntu.com/4144-1/
- https://security.netapp.com/advisory/ntap-20191004-0001/
- https://usn.ubuntu.com/4147-1/
- https://support.f5.com/csp/article/K32592426?utm_source=f5support&%3Butm_medium=RSS