MNBSD-2019-1: pts(4) write-after-free on close of posix_openpt descriptor

Severity: Unknown

Affected Package: kernel

Summary: pts(4) write-after-free on close of posix_openpt descriptor

Description

The code that handles close(2) of a descriptor created by posix_openpt(2) fails to undo the configuration that causes SIGIO to be raised. This bug can lead to a write-after-free of kernel memory, which malicious code may use to gain root privileges or escape a jail.

Affected Versions

kernel

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2019-5606

Published: July 24, 2019
Last Modified: July 24, 2019