Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2019-5023 Details

Description

An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linux-4.9.8-test1 to 4.9.24-test7, grsecurity official from version grsecurity-3.1-4.9.8-201702060653 to grsecurity-3.1-4.9.24-201704252333, grsecurity unofficial from version v4.9.25-unofficialgrsec to v4.9.74-unofficialgrsec. PaX adds a temp buffer to the read_kmem function, which is never freed when an invalid address is supplied. This results in a memory leakage that can lead to a crash of the system. An attacker needs to induce a read to /dev/kmem using an invalid address to exploit this vulnerability.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-772Missing Release of Resource after Effective Lifetime[email protected]
CWE-401Missing Release of Memory after Effective Lifetime[email protected]

Affected Products

ProductVersions
opensrcsec grsecurity
>= 3.1-4.9.8-201702060653, <= 3.1-4.9.24-201704252333
>= 4.9.25, <= 4.9.74

CPE

  • cpe:2.3:a:opensrcsec:grsecurity:*:*:*:*:official:*:*:*
  • cpe:2.3:a:opensrcsec:grsecurity:*:*:*:*:unofficial:*:*:*

Remediation

  • No remediation found in references.
opensrcsec pax
>= pax-linux-4.9.8-test1, <= pax-linux-4.9.8-test7

CPE

  • cpe:2.3:a:opensrcsec:pax:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2019-5023
NVD Published Date:
Oct 31, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]