{"api_version":"1","generated_at":"2026-07-23T13:40:08+00:00","cve":"CVE-2019-11599","urls":{"html":"https://cve.report/CVE-2019-11599","api":"https://cve.report/api/cve/CVE-2019-11599.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-11599","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-11599"},"summary":{"title":"CVE-2019-11599","description":"The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c, mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-04-29 18:29:00","updated_at":"2023-11-07 03:03:00"},"problem_types":["CWE-667"],"metrics":[],"references":[{"url":"https://usn.ubuntu.com/4069-2/","name":"USN-4069-2","refsource":"UBUNTU","tags":[],"title":"USN-4069-2: Linux kernel (HWE) vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Jul/33","name":"20190722 [slackware-security] Slackware 14.2 kernel (SSA:2019-202-01)","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: [slackware-security]  Slackware 14.2 kernel (SSA:2019-202-01)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:2029","name":"RHSA-2019:2029","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.f5.com/csp/article/K51674118?utm_source=f5support&amp;utm_medium=RSS","name":"https://support.f5.com/csp/article/K51674118?utm_source=f5support&amp;utm_medium=RSS","refsource":"CONFIRM","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2019/04/29/2","name":"[oss-security] 20190429 Re: Linux kernel: multiple issues","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: Linux kernel: multiple issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Jun/26","name":"20190618 [SECURITY] [DSA 4465-1] linux security update","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: [SECURITY] [DSA 4465-1] linux security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html","name":"[debian-lts-announce] 20190528 [SECURITY] [DLA 1799-2] linux security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1799-2] linux security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=04f5866e41fb70690e28397487d8bd8eea7d712a","name":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=04f5866e41fb70690e28397487d8bd8eea7d712a","refsource":"MISC","tags":["Mailing List","Patch","Vendor Advisory"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/108113","name":"108113","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel CVE-2019-11599 Local Race Condition Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://packetstormsecurity.com/files/152663/Linux-Missing-Lockdown.html","name":"http://packetstormsecurity.com/files/152663/Linux-Missing-Lockdown.html","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Linux Missing Lockdown ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/4069-1/","name":"USN-4069-1","refsource":"UBUNTU","tags":[],"title":"USN-4069-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:3517","name":"RHSA-2019:3517","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00014.html","name":"openSUSE-SU-2019:1716","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2019:1716-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10","name":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10","refsource":"MISC","tags":["Mailing List","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html","name":"[debian-lts-announce] 20190528 [SECURITY] [DLA 1799-1] linux security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1799-1] linux security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.f5.com/csp/article/K51674118","name":"https://support.f5.com/csp/article/K51674118","refsource":"CONFIRM","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:2043","name":"RHSA-2019:2043","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.netapp.com/advisory/ntap-20190517-0002/","name":"https://security.netapp.com/advisory/ntap-20190517-0002/","refsource":"CONFIRM","tags":[],"title":"May 7th 2019 Linux Kernel Vulnerabilities in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2019/dsa-4465","name":"DSA-4465","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4465-1 linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114","name":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114","refsource":"MISC","tags":["Mailing List","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1790","name":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1790","refsource":"MISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"1790 - \n \n \n project-zero -\n \n \n Project Zero - \n \n Monorail","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/4095-1/","name":"USN-4095-1","refsource":"UBUNTU","tags":[],"title":"USN-4095-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2019/04/30/1","name":"[oss-security] 20190430 Re: Linux kernel: multiple issues","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: Linux kernel: multiple issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.netapp.com/advisory/ntap-20200608-0001/","name":"https://security.netapp.com/advisory/ntap-20200608-0001/","refsource":"CONFIRM","tags":[],"title":"May 2020 Linux Kernel Vulnerabilities in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2020:0543","name":"RHSA-2020:0543","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/4118-1/","name":"USN-4118-1","refsource":"UBUNTU","tags":[],"title":"USN-4118-1: Linux kernel (AWS) vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.37","name":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.37","refsource":"MISC","tags":["Mailing List","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/torvalds/linux/commit/04f5866e41fb70690e28397487d8bd8eea7d712a","name":"https://github.com/torvalds/linux/commit/04f5866e41fb70690e28397487d8bd8eea7d712a","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"coredump: fix race condition between mmget_not_zero()/get_task_mm() a… · torvalds/linux@04f5866 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2020:0100","name":"RHSA-2020:0100","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00025.html","name":"openSUSE-SU-2019:1757","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2019:1757-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2019/04/29/1","name":"[oss-security] 20190429 Linux kernel: multiple issues","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Linux kernel: multiple issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/4115-1/","name":"USN-4115-1","refsource":"UBUNTU","tags":[],"title":"USN-4115-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2020:0179","name":"RHSA-2020:0179","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/06/msg00011.html","name":"[debian-lts-announce] 20190618 [SECURITY] [DLA 1824-1] linux-4.9 security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1824-1] linux-4.9 security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html","name":"http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html","refsource":"MISC","tags":[],"title":"Slackware Security Advisory - Slackware 14.2 kernel Updates ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:3309","name":"RHSA-2019:3309","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","name":"https://www.oracle.com/security-alerts/cpuApr2021.html","refsource":"MISC","tags":[],"title":"Oracle Critical Patch Update Advisory - April 2021","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/46781/","name":"46781","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Linux - Missing Locking Between ELF coredump code and userfaultfd VMA Modification - Linux dos Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2020:0103","name":"RHSA-2020:0103","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.f5.com/csp/article/K51674118?utm_source=f5support&amp%3Butm_medium=RSS","name":"https://support.f5.com/csp/article/K51674118?utm_source=f5support&amp%3Butm_medium=RSS","refsource":"","tags":[],"title":"myF5","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11599","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11599","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"11599","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"11599","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-11599","qid":"375678","title":"F5 BIG-IP ASM,LTM,APM BIG-IP Linux Kernel Vulnerability (K51674118)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-11599","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c, mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MLIST","name":"[oss-security] 20190429 Re: Linux kernel: multiple issues","url":"http://www.openwall.com/lists/oss-security/2019/04/29/2"},{"refsource":"MLIST","name":"[oss-security] 20190429 Linux kernel: multiple issues","url":"http://www.openwall.com/lists/oss-security/2019/04/29/1"},{"refsource":"MLIST","name":"[oss-security] 20190430 Re: Linux kernel: multiple issues","url":"http://www.openwall.com/lists/oss-security/2019/04/30/1"},{"refsource":"EXPLOIT-DB","name":"46781","url":"https://www.exploit-db.com/exploits/46781/"},{"refsource":"BID","name":"108113","url":"http://www.securityfocus.com/bid/108113"},{"refsource":"MLIST","name":"[debian-lts-announce] 20190528 [SECURITY] [DLA 1799-1] linux security update","url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html"},{"refsource":"MLIST","name":"[debian-lts-announce] 20190528 [SECURITY] [DLA 1799-2] linux security update","url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html"},{"refsource":"DEBIAN","name":"DSA-4465","url":"https://www.debian.org/security/2019/dsa-4465"},{"refsource":"MLIST","name":"[debian-lts-announce] 20190618 [SECURITY] [DLA 1824-1] linux-4.9 security update","url":"https://lists.debian.org/debian-lts-announce/2019/06/msg00011.html"},{"refsource":"BUGTRAQ","name":"20190618 [SECURITY] [DSA 4465-1] linux security update","url":"https://seclists.org/bugtraq/2019/Jun/26"},{"refsource":"SUSE","name":"openSUSE-SU-2019:1716","url":"http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00014.html"},{"refsource":"SUSE","name":"openSUSE-SU-2019:1757","url":"http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00025.html"},{"refsource":"BUGTRAQ","name":"20190722 [slackware-security] Slackware 14.2 kernel (SSA:2019-202-01)","url":"https://seclists.org/bugtraq/2019/Jul/33"},{"refsource":"UBUNTU","name":"USN-4069-1","url":"https://usn.ubuntu.com/4069-1/"},{"refsource":"UBUNTU","name":"USN-4069-2","url":"https://usn.ubuntu.com/4069-2/"},{"refsource":"REDHAT","name":"RHSA-2019:2043","url":"https://access.redhat.com/errata/RHSA-2019:2043"},{"refsource":"REDHAT","name":"RHSA-2019:2029","url":"https://access.redhat.com/errata/RHSA-2019:2029"},{"refsource":"UBUNTU","name":"USN-4095-1","url":"https://usn.ubuntu.com/4095-1/"},{"refsource":"UBUNTU","name":"USN-4115-1","url":"https://usn.ubuntu.com/4115-1/"},{"refsource":"UBUNTU","name":"USN-4118-1","url":"https://usn.ubuntu.com/4118-1/"},{"refsource":"REDHAT","name":"RHSA-2019:3309","url":"https://access.redhat.com/errata/RHSA-2019:3309"},{"refsource":"REDHAT","name":"RHSA-2019:3517","url":"https://access.redhat.com/errata/RHSA-2019:3517"},{"refsource":"REDHAT","name":"RHSA-2020:0100","url":"https://access.redhat.com/errata/RHSA-2020:0100"},{"refsource":"REDHAT","name":"RHSA-2020:0103","url":"https://access.redhat.com/errata/RHSA-2020:0103"},{"refsource":"REDHAT","name":"RHSA-2020:0179","url":"https://access.redhat.com/errata/RHSA-2020:0179"},{"refsource":"REDHAT","name":"RHSA-2020:0543","url":"https://access.redhat.com/errata/RHSA-2020:0543"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","refsource":"MISC","name":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114","refsource":"MISC","name":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.37","refsource":"MISC","name":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.37"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10","refsource":"MISC","name":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10"},{"url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1790","refsource":"MISC","name":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1790"},{"url":"https://github.com/torvalds/linux/commit/04f5866e41fb70690e28397487d8bd8eea7d712a","refsource":"MISC","name":"https://github.com/torvalds/linux/commit/04f5866e41fb70690e28397487d8bd8eea7d712a"},{"url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=04f5866e41fb70690e28397487d8bd8eea7d712a","refsource":"MISC","name":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=04f5866e41fb70690e28397487d8bd8eea7d712a"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/152663/Linux-Missing-Lockdown.html","url":"http://packetstormsecurity.com/files/152663/Linux-Missing-Lockdown.html"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20190517-0002/","url":"https://security.netapp.com/advisory/ntap-20190517-0002/"},{"refsource":"CONFIRM","name":"https://support.f5.com/csp/article/K51674118","url":"https://support.f5.com/csp/article/K51674118"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html","url":"http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html"},{"refsource":"CONFIRM","name":"https://support.f5.com/csp/article/K51674118?utm_source=f5support&amp;utm_medium=RSS","url":"https://support.f5.com/csp/article/K51674118?utm_source=f5support&amp;utm_medium=RSS"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20200608-0001/","url":"https://security.netapp.com/advisory/ntap-20200608-0001/"}]}},"nvd":{"publishedDate":"2019-04-29 18:29:00","lastModifiedDate":"2023-11-07 03:03:00","problem_types":["CWE-667"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7,"baseSeverity":"HIGH"},"exploitabilityScore":1,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":6.9},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.0.10","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"11599","Ordinal":"149900","Title":"CVE-2019-11599","CVE":"CVE-2019-11599","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"11599","Ordinal":"1","NoteData":"The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c, mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"11599","Ordinal":"2","NoteData":"2019-04-29","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"11599","Ordinal":"3","NoteData":"2021-06-14","Type":"Other","Title":"Modified"}]}}}