A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10140 | Issue Tracking Third Party Advisory |
https://security.netapp.com/advisory/ntap-20190905-0002/ |
Information
Published : 2019-08-15 10:15
Updated : 2023-02-12 15:32
NVD link : CVE-2019-10140
Mitre link : CVE-2019-10140
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
redhat
- enterprise_linux
linux
- linux_kernel