Tracker / CVE-2019-15538
CVE-2019-15538
High 7.5
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| debian | debian_linux |
| fedoraproject | fedora |
| linux | linux_kernel |
| linux | linux_kernel · 4.14 → 4.14.141 |
| linux | linux_kernel · 4.19 → 4.19.69 |
| linux | linux_kernel · 4.7 → 4.9.191 |
| linux | linux_kernel · 5.2 → 5.2.11 |
| netapp | aff_a700s_firmware |
| netapp | data_availability_services |
| netapp | h300e_firmware |
| netapp | h300s_firmware |
| netapp | h410c_firmware |
| netapp | h410s_firmware |
| netapp | h500e_firmware |
| netapp | h500s_firmware |
| netapp | h610s_firmware |
| netapp | h700e_firmware |
| netapp | h700s_firmware |
| netapp | hci_management_node |
| netapp | solidfire |
| opensuse | leap |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.