{"schema_version":"1.7.5","id":"CVE-2019-15538","published":"2019-08-25T16:15:11.033Z","modified":"2026-04-02T01:32:55.167489Z","related":["SUSE-SU-2019:2412-1","SUSE-SU-2019:2414-1","SUSE-SU-2019:2424-1","SUSE-SU-2019:2648-1","SUSE-SU-2019:2651-1","SUSE-SU-2019:2658-1","SUSE-SU-2019:2738-1","SUSE-SU-2019:2756-1","openSUSE-SU-2019:2173-1","openSUSE-SU-2019:2181-1"],"details":"An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git","events":[{"introduced":"0"},{"fixed":"1fb254aa983bf190cfd685d40c64a480a9bafaee"}]},{"type":"GIT","repo":"https://github.com/torvalds/linux","events":[{"introduced":"0"},{"last_affected":"4d856f72c10ecb060868ed10ff1b1453943fc6c8"},{"introduced":"0"},{"last_affected":"5f9e832c137075045d15cd6899ab0505cfb2ca4b"},{"introduced":"0"},{"last_affected":"609488bc979f99f805f34e9a32c1e3b71179d10b"},{"introduced":"0"},{"last_affected":"e21a712a9685488f5ce80495b37b9fdbe96c230d"},{"introduced":"0"},{"last_affected":"d45331b00ddb179e291766617259261c112db872"},{"introduced":"0"},{"last_affected":"d1abaeb3be7b5fa6d7a1fbbd2e14e3310005c4c1"},{"introduced":"0"},{"last_affected":"a55aa89aab90fae7c815b0551b07be37db359d76"},{"fixed":"1fb254aa983bf190cfd685d40c64a480a9bafaee"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"5.3-NA"},{"introduced":"0"},{"last_affected":"5.3-rc1"},{"introduced":"0"},{"last_affected":"5.3-rc2"},{"introduced":"0"},{"last_affected":"5.3-rc3"},{"introduced":"0"},{"last_affected":"5.3-rc4"},{"introduced":"0"},{"last_affected":"5.3-rc5"},{"introduced":"0"},{"last_affected":"5.3-rc6"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15538.json","unresolved_ranges":[{"events":[{"introduced":"4.7"},{"fixed":"4.9.191"}]},{"events":[{"introduced":"4.14"},{"fixed":"4.14.141"}]},{"events":[{"introduced":"4.19"},{"fixed":"4.19.69"}]},{"events":[{"introduced":"5.2"},{"fixed":"5.2.11"}]},{"events":[{"introduced":"0"},{"last_affected":"16.04"}]},{"events":[{"introduced":"0"},{"last_affected":"18.04"}]},{"events":[{"introduced":"0"},{"last_affected":"19.04"}]},{"events":[{"introduced":"0"},{"last_affected":"15.0"}]},{"events":[{"introduced":"0"},{"last_affected":"15.1"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"29"}]},{"events":[{"introduced":"0"},{"last_affected":"30"}]}]}}],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/"},{"type":"WEB","url":"https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/"},{"type":"WEB","url":"https://support.f5.com/csp/article/K32592426?utm_source=f5support&amp%3Butm_medium=RSS"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/"},{"type":"WEB","url":"https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191004-0001/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4144-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4147-1/"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html"},{"type":"FIX","url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee"},{"type":"FIX","url":"https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}