SB2019081534 - NULL pointer dereference in Linux kernel
Published: August 15, 2019 Updated: August 27, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2019-10140)
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the overlayfs implementation due to a NULL pointer dereference error in the "ovl_posix_acl_create" function in "the fs/overlayfs/dir.c" file. A local authenticated attacker with the ability to create directories on overlayfs can send malicious input to the system, trigger a NULL pointer dereference condition and cause a denial of service (DOS).
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.