CVE-2019-8606: Race Condition
Published May 13, 2019
·Updated
IOKit. A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Other sources
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Mojave 10.14.5. A local user may be able to load unsigned kernel extensions.
Credit
Phoenhex, qwerty@@_niklasb, @@qwertyoruiopz, @@bkth_(Trend Micro)
Affected Software
4 affected componentsFixes available
Apple macOS Mojave<10.14.5
10.14.5
Apple High Sierra
Apple Sierra
Apple iOS and macOS<10.14.5
Event History
Dec 18, 2019
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8603
- CVE-2019-8635
- CVE-2019-8590
- CVE-2019-8640
- CVE-2019-2102
- CVE-2019-8592
- CVE-2019-8585
- CVE-2019-8582
- CVE-2019-8589
- CVE-2019-8560
- CVE-2019-8634
- CVE-2019-8616
- CVE-2019-8629
- CVE-2018-4456
- CVE-2019-8606
- CVE-2019-8633
- CVE-2019-8525
- CVE-2019-8547
- CVE-2019-8576
- CVE-2019-8591
- CVE-2019-8573
- CVE-2019-8631
- CVE-2018-12126
- CVE-2018-12127
- CVE-2018-12130
- CVE-2019-11091
- CVE-2019-8604
- CVE-2019-8577
- CVE-2019-8600
- CVE-2019-8598
- CVE-2019-8602
- CVE-2019-8568
- CVE-2019-8574
- CVE-2019-8569
- CVE-2019-6237
- CVE-2019-8571
- CVE-2019-8583
- CVE-2019-8584
- CVE-2019-8586
- CVE-2019-8587
- CVE-2019-8594
- CVE-2019-8595
- CVE-2019-8596
- CVE-2019-8597
- CVE-2019-8601
- CVE-2019-8608
- CVE-2019-8609
- CVE-2019-8610
- CVE-2019-8611
- CVE-2019-8615
- CVE-2019-8619
- CVE-2019-8622
- CVE-2019-8623
- CVE-2019-8628
- CVE-2019-8607
- CVE-2019-8612
Frequently Asked Questions
1
What is the severity of CVE-2019-8606?
The severity of CVE-2019-8606 is high.
2
How does CVE-2019-8606 impact macOS Mojave?
CVE-2019-8606 allows a local user to load unsigned kernel extensions in macOS Mojave.
3
How can I fix CVE-2019-8606?
To fix CVE-2019-8606, update your macOS Mojave to version 10.14.5 or later.
4
What are the affected software versions of CVE-2019-8606?
CVE-2019-8606 affects macOS Mojave 10.14.5 and earlier.
5
What is the Common Weakness Enumeration ID of CVE-2019-8606?
The Common Weakness Enumeration ID of CVE-2019-8606 is CWE-362.