CVE-2019-19319

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, aka CID-345c0dbf3a30.

References

http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html

https://bugzilla.suse.com/show_bug.cgi?id=1158021

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=345c0dbf3a30

https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19319

https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html

https://security.netapp.com/advisory/ntap-20200103-0001/

https://usn.ubuntu.com/4391-1/

https://www.debian.org/security/2020/dsa-4698

Details

Source: MITRE

Published: 2019-11-27

Updated: 2021-02-09

Type: CWE-787

Risk Information

CVSS v2

Base Score: 4.4

Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 0.6

Severity: MEDIUM

Tenable Plugins

View all (25 total)

IDNameProductFamilySeverity
149098EulerOS 2.0 SP3 : kernel (EulerOS-SA-2021-1808)NessusHuawei Local Security Checks
high
147318NewStart CGSL MAIN 6.02 : kernel Multiple Vulnerabilities (NS-SA-2021-0078)NessusNewStart CGSL Local Security Checks
high
145806CentOS 8 : kernel (CESA-2020:4431)NessusCentOS Local Security Checks
medium
142430RHEL 8 : kernel (RHSA-2020:4431)NessusRed Hat Local Security Checks
medium
142382RHEL 8 : kernel-rt (RHSA-2020:4609)NessusRed Hat Local Security Checks
medium
138272SUSE SLES15 Security Update : kernel (SUSE-SU-2020:1663-1)NessusSuSE Local Security Checks
critical
137516EulerOS 2.0 SP2 : kernel (EulerOS-SA-2020-1674)NessusHuawei Local Security Checks
critical
137391Slackware 14.2 : Slackware 14.2 kernel (SSA:2020-163-01)NessusSlackware Local Security Checks
medium
137340Debian DSA-4698-1 : linux - security updateNessusDebian Local Security Checks
medium
137339Debian DLA-2242-1 : linux-4.9 security updateNessusDebian Local Security Checks
medium
137301Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4391-1)NessusUbuntu Local Security Checks
medium
137283Debian DLA-2241-2 : linux security updateNessusDebian Local Security Checks
medium
137100Amazon Linux AMI : kernel (ALAS-2020-1377)NessusAmazon Linux Local Security Checks
medium
137088Amazon Linux 2 : kernel (ALAS-2020-1431)NessusAmazon Linux Local Security Checks
medium
136782SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1275-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusSuSE Local Security Checks
critical
136661SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1255-1)NessusSuSE Local Security Checks
critical
136555Photon OS 1.0: Linux PHSA-2020-1.0-0292NessusPhotonOS Local Security Checks
medium
136407Photon OS 2.0: Linux PHSA-2020-2.0-0239NessusPhotonOS Local Security Checks
medium
134559openSUSE Security Update : the Linux Kernel (openSUSE-2020-336)NessusSuSE Local Security Checks
critical
134363SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:0613-1)NessusSuSE Local Security Checks
critical
134293SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0584-1)NessusSuSE Local Security Checks
critical
134292SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0580-1)NessusSuSE Local Security Checks
critical
134289SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:0560-1)NessusSuSE Local Security Checks
critical
134288SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0559-1)NessusSuSE Local Security Checks
critical
132925SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0093-1)NessusSuSE Local Security Checks
critical