Severity: Unknown
Affected Package: kernel
Summary: struct file reference counter overflow in mqueuefs
System calls operating on file descriptors obtain a reference to the relevant struct file which, due to a programming error, was not always put back. This could be used to overflow the reference counter of the affected struct file. A local user could exploit this to gain access to files, directories, and sockets opened by other users, escape a jail, or, for a jailed root user, obtain root privileges on the host. This advisory addressed the flaw in the 32-bit compatibility layer.
No specific recommendations provided.
Aliases: CVE-2019-5603
Published: August 22, 2019
Last Modified: August 22, 2019