ISOMAN

CVE

CVE-2019-15918

An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely updated after a change from smb30 to smb21.

Severity
HIGH
CVSS
7.8
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10
  2. https://github.com/torvalds/linux/commit/b57a55e2200ede754e4dc9cce4ba9402544b9365
  3. https://security.netapp.com/advisory/ntap-20191004-0001/
  4. https://usn.ubuntu.com/4162-1/
  5. https://usn.ubuntu.com/4162-2/
  6. https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10
  7. https://github.com/torvalds/linux/commit/b57a55e2200ede754e4dc9cce4ba9402544b9365
  8. https://security.netapp.com/advisory/ntap-20191004-0001/
  9. https://usn.ubuntu.com/4162-1/
  10. https://usn.ubuntu.com/4162-2/