CVE-2019-15538

Modified
Published: 25 Aug 2019, 15:25
Last modified:05 Aug 2024, 00:49

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
16.43% MEDIUM
16% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Aug 2019, 15:25
Published
Vulnerability first disclosed
05 Aug 2024, 00:49
Last Modified
Vulnerability information updated

Description

An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 16.43% Percentile: 95%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.04

  • debiandebian_linux

    8.0

  • fedoraprojectfedora

    29 | 30

  • linuxlinux_kernel

    ≥ 4.7, < 4.9.191 | ≥ 4.14, < 4.14.141 | ≥ 4.19, < 4.19.69 | ≥ 5.2, < 5.2.11 | 5.3 | 5.3:rc1 | 5.3:rc2 | 5.3:rc3 | 5.3:rc4 | 5.3:rc5 | 5.3:rc6

  • netappaff_a700s

    na

  • netappdata_availability_services

    na

  • netapph300e_firmware

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e_firmware

    na

  • netapph500s_firmware

    na

  • netapph610s_firmware

    na

  • netapph700e_firmware

    na

  • netapph700s_firmware

    na

  • netapphci_management_node

    na

  • netappsolidfire

    na

  • opensuseleap

    15.0 | 15.1

References (14)