CVE-2019-10140 PUBLISHED CVSS 5.5 MEDIUM

A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).

EPSS 0.03% · 9.3th percentile

Risk Scores

CVSS v3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.03%
9.3th percentile

Affected Products

VendorProductVersions
linuxlinux_kernel0
redhatenterprise_linux7.0
OpenSourcekernel:up to kernel-3.10

Timeline

References

Open in Interactive Console →