5.5

CVE-2019-11833

fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 5.1.2
FedoraprojectFedora Version29
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version19.04
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Eus Version8.1
RedhatEnterprise Linux Eus Version8.2
RedhatEnterprise Linux Eus Version8.4
RedhatEnterprise Linux Eus Version8.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

https://usn.ubuntu.com/4118-1/
Third Party Advisory
https://usn.ubuntu.com/4095-2/
Third Party Advisory
https://seclists.org/bugtraq/2019/Jun/26
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4069-1/
Third Party Advisory
https://usn.ubuntu.com/4069-2/
Third Party Advisory
https://usn.ubuntu.com/4076-1/
Third Party Advisory
https://usn.ubuntu.com/4068-1/
Third Party Advisory
https://usn.ubuntu.com/4068-2/
Third Party Advisory
http://www.securityfocus.com/bid/108372
Third Party Advisory
Broken Link
VDB Entry