In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9213.json"
[
{
"digest": {
"function_hash": "227468924062753994952315228510445499087",
"length": 1171.0
},
"signature_version": "v1",
"target": {
"file": "mm/mmap.c",
"function": "expand_downwards"
},
"signature_type": "Function",
"id": "CVE-2019-9213-343db19f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0a1d52994d440e21def1c2174932410b4f2a98a1",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"212933224945171062954352439591057879880",
"152394536467846874539272617740270719215",
"221696730177860719812457378279626260537",
"133246617331142059222571319563072498828",
"75162677146451014204869771542129291480",
"156611071841525440859148843434392812414",
"46757694792764894529264931529424628922",
"109555813643326487305085830003991970954"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "mm/mmap.c"
},
"signature_type": "Line",
"id": "CVE-2019-9213-7b42656f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0a1d52994d440e21def1c2174932410b4f2a98a1",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9213.json"
[
{
"digest": {
"function_hash": "227468924062753994952315228510445499087",
"length": 1171.0
},
"signature_version": "v1",
"target": {
"file": "mm/mmap.c",
"function": "expand_downwards"
},
"signature_type": "Function",
"id": "CVE-2019-9213-577d1869",
"source": "https://github.com/torvalds/linux/commit/0a1d52994d440e21def1c2174932410b4f2a98a1",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"212933224945171062954352439591057879880",
"152394536467846874539272617740270719215",
"221696730177860719812457378279626260537",
"133246617331142059222571319563072498828",
"75162677146451014204869771542129291480",
"156611071841525440859148843434392812414",
"46757694792764894529264931529424628922",
"109555813643326487305085830003991970954"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "mm/mmap.c"
},
"signature_type": "Line",
"id": "CVE-2019-9213-742ee29b",
"source": "https://github.com/torvalds/linux/commit/0a1d52994d440e21def1c2174932410b4f2a98a1",
"deprecated": false
}
]