CVE-2019-15538

An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html Mailing List Third Party Advisory
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee Mailing List Patch Vendor Advisory
https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee Patch Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/
https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/
https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local
https://security.netapp.com/advisory/ntap-20191004-0001/ Third Party Advisory
https://support.f5.com/csp/article/K32592426?utm_source=f5support&amp%3Butm_medium=RSS
https://usn.ubuntu.com/4144-1/ Third Party Advisory
https://usn.ubuntu.com/4147-1/ Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html Mailing List Third Party Advisory
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee Mailing List Patch Vendor Advisory
https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee Patch Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/
https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/
https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local
https://security.netapp.com/advisory/ntap-20191004-0001/ Third Party Advisory
https://support.f5.com/csp/article/K32592426?utm_source=f5support&amp%3Butm_medium=RSS
https://usn.ubuntu.com/4144-1/ Third Party Advisory
https://usn.ubuntu.com/4147-1/ Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.3:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.3:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.3:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.3:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.3:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.3:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.3:rc6:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:aff_a700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:aff_a700s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*

Configuration 14 (hide)

OR cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 15 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 16 (hide)

OR cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

History

21 Nov 2024, 04:28

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html - Mailing List, Third Party Advisory
References () https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee - Mailing List, Patch, Vendor Advisory () https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee - Mailing List, Patch, Vendor Advisory
References () https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee - Patch, Third Party Advisory () https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee - Patch, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/ -
References () https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/ - () https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/ -
References () https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local - () https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local -
References () https://security.netapp.com/advisory/ntap-20191004-0001/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20191004-0001/ - Third Party Advisory
References () https://support.f5.com/csp/article/K32592426?utm_source=f5support&amp%3Butm_medium=RSS - () https://support.f5.com/csp/article/K32592426?utm_source=f5support&amp%3Butm_medium=RSS -
References () https://usn.ubuntu.com/4144-1/ - Third Party Advisory () https://usn.ubuntu.com/4144-1/ - Third Party Advisory
References () https://usn.ubuntu.com/4147-1/ - Third Party Advisory () https://usn.ubuntu.com/4147-1/ - Third Party Advisory

07 Nov 2023, 03:05

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/', 'name': 'FEDORA-2019-4c91a2f76e', 'tags': ['Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lore.kernel.org/linux-xfs/20190823192433.GA8736@eldamar.local', 'name': 'https://lore.kernel.org/linux-xfs/20190823192433.GA8736@eldamar.local', 'tags': ['Mailing List', 'Patch', 'Vendor Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/', 'name': 'FEDORA-2019-97380355ae', 'tags': ['Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://support.f5.com/csp/article/K32592426?utm_source=f5support&utm_medium=RSS', 'name': 'https://support.f5.com/csp/article/K32592426?utm_source=f5support&utm_medium=RSS', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • {'url': 'https://lore.kernel.org/linux-xfs/20190823035528.GH1037422@magnolia/', 'name': 'https://lore.kernel.org/linux-xfs/20190823035528.GH1037422@magnolia/', 'tags': ['Mailing List', 'Patch', 'Vendor Advisory'], 'refsource': 'MISC'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/ -
  • () https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/ -
  • () https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/ -
  • () https://support.f5.com/csp/article/K32592426?utm_source=f5support&amp%3Butm_medium=RSS -

Information

Published : 2019-08-25 16:15

Updated : 2024-11-21 04:28


NVD link : CVE-2019-15538

Mitre link : CVE-2019-15538

CVE.ORG link : CVE-2019-15538


JSON object : View

Products Affected

netapp

  • h300s_firmware
  • h700e_firmware
  • aff_a700s
  • hci_management_node
  • h410s_firmware
  • h410c_firmware
  • data_availability_services
  • aff_a700s_firmware
  • h300e
  • h300s
  • h610s_firmware
  • h700s
  • h500e_firmware
  • h300e_firmware
  • h410c
  • h410s
  • h500s_firmware
  • h700e
  • h500s
  • h500e
  • h700s_firmware
  • solidfire
  • h610s

fedoraproject

  • fedora

canonical

  • ubuntu_linux

opensuse

  • leap

linux

  • linux_kernel

debian

  • debian_linux
CWE
CWE-400

Uncontrolled Resource Consumption