9.3
CVE-2019-19816
- EPSS 3.29%
- Veröffentlicht 17.12.2019 06:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:26
- Erkennungen
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.12 < 4.4.247
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.247
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.210
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.137
Linux ≫ Linux Kernel Version >= 4.20 < 5.2
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Debian ≫ Debian Linux Version 9.0
Netapp ≫ Active Iq Unified Manager SwPlatform vmware_vsphere Version >= 9.5
Netapp ≫ Data Availability Services Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Steelstore Cloud Integrated Storage Version -
Netapp ≫ Aff A700s Firmware Version -
Netapp ≫ Fas8300 Firmware Version -
Netapp ≫ Fas8700 Firmware Version -
Netapp ≫ Aff A400 Firmware Version -
Netapp ≫ H610s Firmware Version -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.29% | 0.869 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
https://usn.ubuntu.com/4414-1/
https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html
https://security.netapp.com/advisory/ntap-20200103-0001/
https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19816