DEBIAN-CVE-2019-11599
Advisory lineage Upstream: 1 Downstream: 3
Upstream
Downstream
Published: 29 Apr 2019, 18:29
Last modified:28 Apr 2026, 20:20
Vulnerability Summary
Overall Risk (default)
medium
28/100 CVSS Score
7 HIGH
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
29 Apr 2019, 18:29
Published
Vulnerability first disclosed
28 Apr 2026, 20:20
Last Modified
Vulnerability information updated
Description
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c, mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.
CVSS Metrics
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- debian•linux
< 4.19.37-1 | < 4.19.37-1 | < 4.19.37-1 | < 4.19.37-1