CVE-2019-11811
There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c, drivers/char/ipmi/ipmi_si_mem_io.c, and drivers/char/ipmi/ipmi_si_port_io.c.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c, drivers/char/ipmi/ipmi_si_mem_io.c, and drivers/char/ipmi/ipmi_si_port_io.c.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- linux/linux kernel · opensuse/leap · redhat/enterprise linux · redhat/enterprise linux aus · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00071.htmlThird Party Advisory
- http://www.securityfocus.com/bid/108410Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1873Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1891Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1959Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1971Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4057Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4058Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0036Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.4Release Notes, Vendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=401e7e88d4ef80188ffa07095ac00456f901b8c4Patch, Vendor Advisory
- https://github.com/torvalds/linux/commit/401e7e88d4ef80188ffa07095ac00456f901b8c4Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190719-0003/Third Party Advisory
- https://support.f5.com/csp/article/K01512680Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00071.htmlThird Party Advisory
- http://www.securityfocus.com/bid/108410Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1873Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1891Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1959Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1971Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4057Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4058Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0036Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.4Release Notes, Vendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=401e7e88d4ef80188ffa07095ac00456f901b8c4Patch, Vendor Advisory
- https://github.com/torvalds/linux/commit/401e7e88d4ef80188ffa07095ac00456f901b8c4Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190719-0003/Third Party Advisory
- https://support.f5.com/csp/article/K01512680Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.