imPC@ndo IT

Tracker / CVE-2019-15918

CVE-2019-15918

High 7.8

An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely updated after a change from smb30 to smb21.

Affected products and versions

canonical ubuntu_linux
linux linux_kernel · 4.13.5 → 4.14.166
linux linux_kernel · 4.15 → 4.19.73
linux linux_kernel · 4.20 → 5.0.10

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References