CVE-2019-11191

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-11191
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11191.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-11191
Downstream
Published
2019-04-12T00:29:00Z
Modified
2025-08-09T20:01:26Z
Severity
  • 2.5 (Low) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The Linux kernel through 5.0.7, when CONFIGIA32AOUT is enabled and ia32aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because installexeccreds() is called too late in loadaoutbinary() in fs/binfmtaout.c, and thus the ptracemayaccess() check has a race condition when reading /proc/pid/stat. NOTE: the software maintainer disputes that this is a vulnerability because ASLR for a.out format executables has never been supported

Database specific
{
    "isDisputed": true
}
References

Affected packages