LinuxÄں˾ºÕùǰÌá·ì϶£¨CVE-2019-11815£©

°ä²¼¹¦·ò 2019-05-14


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²¼¾°ÃèÊö


×êÑÐÈËÔ±ÔÚ5.0.8֮ǰµÄLinuxÄÚºËÖз¢ÏÖ¾ºÕùǰÌá·ì϶£¨CVE-2019-11815£©¡£


ƾ¾ÝCVSS  3.0µÄÓ°ÏìÖ¸±ê £¬CVE-2019-11815·ì϶ӵÓи߻úÃÜÐÔ £¬ÆëÈ«ÐԺͿÉÓÃÐÔ £¬ÕâʹµÃDZÔÚ¹¥»÷ÕßÄܹ»½Ó¼ûËùÓÐ×ÊÔ´ £¬Åú¸ÄÈκÎÎļþ¡£


ÕýÈçCommon Weakness Enumeration£¨CWE£©ÖÐËùÏêÊöµÄ £¬Use-After-FreeȱµãÊÇÓÉÓÚÔÚÄÚ´æ±»¿ªÊͺó³¢ÊÔÒýÓÃÄÚ´æ £¬µ¼ÖÂÈí¼þ±ÀÀ£ £¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£

Ó°ÏìÁìÓò


CVE ID  £º    CVE-2019-11815   
CNNVD£º    CNNVD-201905-195 
·ì϶µÈ¼¶£º   ÖÐΣ
Ó°ÏìÁìÓò£º   Linux kernel 5.0.8֮ǰµÄËùÓа汾

·ì϶ÏêÇé


DZÔڵĹ¥»÷Õß¿ÉÀûÓÃLinuxÄں˵Änet/rds/tcp.cÖеÄrds_tcp_kill_sock TCP/IPÀ´´¥·¢»Ø¾ø·þÎñ£¨DoS£© £¬»òÕßÔÚÒ×Êܹ¥»÷µÄϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½¨¸´½¨Òé


LinuxÄں˿ª·¢ÈËÔ±ÔÚ3ÔÂÏÂÑ®°ä²¼ÁËÕë¶ÔCVE-2019-11815·ì϶µÄ²¹¶¡ £¬²¢½¨¸´ÁË4ÔÂ17ÈÕ°ä²¼µÄLinuxÄÚºË5.0.8°æ±¾Öеķì϶¡£


½¨Òé¸÷Linux¿¯Ðа棨Red Hat £¬Ubuntu £¬SUSEºÍDebian£©±ØÒªÉý¼¶ÖÁ×îаæLinuxÄںˡ£


²Î¿¼Á´½Ó


http://www.securityfocus.com/bid/108283


https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.8


https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cb66ddd156203daefb8d71158036b27b0e2caf63


https://github.com/torvalds/linux/commit/cb66ddd156203daefb8d71158036b27b0e2caf63