5.5

CVE-2019-11833

fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 5.1.2
Fedoraproject ≫ Fedora Version 29
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.46
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00071.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html
Broken Link
https://access.redhat.com/errata/RHSA-2019:3517
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2029
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2043
Third Party Advisory
https://usn.ubuntu.com/4118-1/
Third Party Advisory
https://usn.ubuntu.com/4095-2/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3309
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/06/msg00010.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2019/06/msg00011.html
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Jun/26
Third Party Advisory
Mailing List
https://www.debian.org/security/2019/dsa-4465
Third Party Advisory
https://usn.ubuntu.com/4069-1/
Third Party Advisory
https://usn.ubuntu.com/4069-2/
Third Party Advisory
https://usn.ubuntu.com/4076-1/
Third Party Advisory
https://usn.ubuntu.com/4068-1/
Third Party Advisory
https://usn.ubuntu.com/4068-2/
Third Party Advisory
http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/108372
Third Party Advisory
Broken Link
VDB Entry
https://github.com/torvalds/linux/commit/592acbf16821288ecdc4192c47e3774a4c48bb64
Patch
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GJGZIMGB72TL7OGWRMHIL43WHXFQWU4X/