IBM Support

Security Bulletin: Muluple vulnerabilities in Ubuntu affect IBM Workload Scheduler 9.5

Security Bulletin


Summary

Multiple vulnerabilities have been found in Ubuntu and potentially affect container images of IBM Workload Scheduler 9.5

Vulnerability Details

CVEID:   CVE-2019-11481
DESCRIPTION:   Ubuntu Apport could allow a local attacker to cause a denial of service. By reading user-controlled settings file as the root user, an attacker could exploit this vulnerability to crash Apport or have other unspecified consequences.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171508 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:   CVE-2019-15791
DESCRIPTION:   Ubuntu could allow a local attacker to execute arbitrary code on the system, caused by a reference count underflow in the shiftfs implementation in the kernel. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171524 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2019-15792
DESCRIPTION:   Ubuntu could allow a local attacker to execute arbitrary code on the system, caused by a type confusion in the shiftfs implementation in the kernel. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171526 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2019-15794
DESCRIPTION:   Ubuntu is vulnerable to a denial of service, caused by an issue with the ubuntu-aufs-modified mmap_region function breaks refcounting in overlayfs/shiftfs error path. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171446 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:   CVE-2019-15793
DESCRIPTION:   Ubuntu could allow a local attacker to bypass security restrictions, caused by an issue when not using the correct file system uid/gid when the user namespace of a lower file system is not in the init user namespace. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass the DAC permissions.
CVSS Base score: 7.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/171527 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

IBM Workload Scheduler Distributed  9.5.0 FP01 and earlier


Remediation/Fixes

APAR IJ24525 has been opened to address Ubuntu vulnerabilities affecting IBM Workload Scheduler.
Apar IJ24525 is already included in IBM Workload Scheduler 9.5 FP02, already available on FixCentral.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

26 Apr 2020: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS8GJD","label":"IBM Workload Automation"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.5","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
19 June 2020

UID

ibm16205697