CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.
- Linux Linux Kernel
- < 4.9.162, 4.14.105, 4.19.27, 4.20.14
- Fix
- Available
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 5.7% (92th percentile)
- Weakness
- CWE-476
- NVD status
- Modified
- Published
- 2019-03-05
CVE-2019-9213 at NVD
7 known exploits for CVE-2019-9213
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Access Control in Xen
Reliable Datagram Sockets (RDS) rds_atomic_free_op Privilege Escalation Exploit
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
Reliable Datagram Sockets (RDS) rds_atomic_free_op Privilege Escalation
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
Linux < 4.20.14 - Virtual Address 0 is Mappable via Privileged write() to /proc/*/mem Exploit
Linux < 4.20.14 - Virtual Address 0 is Mappable via Privileged write() to /proc/*/mem