CVE-2019-14898 PUBLISHED

The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.

EPSS 0.05% · 15.6th percentile

Risk Scores

EPSS Score
0.05%
15.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-278.312~14.04.1, 4.4.0-277.311~14.04.1, 4.4.0-276.310~14.04.1
Ubuntu:Pro:14.04:LTSlinux3.13.0-186.237, 3.13.0-187.238, 3.13.0-188.239
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1106.118~14.04.1, 4.15.0-1108.120~14.04.1, 4.15.0-1109.121~14.04.1
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1152.158, 4.4.0-1151.157, 4.4.0-1150.156
Ubuntu:18.04:LTSlinux-hwe-edge0, 5.0.0-15.16~18.04.1, 5.0.0-16.17~18.04.1

Timeline

References

Open in Interactive Console →