CVE-2019-10220 PUBLISHED

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

EPSS 0.74% · 72.9th percentile

Risk Scores

EPSS Score
0.74%
72.9th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-raspi25.3.0-1015.17, 5.3.0-1017.19, 5.4.0-1004.4
Ubuntu:18.04:LTSlinux-oem4.15.0-1059.68, 4.15.0-1057.66, 4.15.0-1056.65
Ubuntu:18.04:LTSlinux-aws4.15.0-1056.58, 4.15.0-1003.3, 4.15.0-1005.5
Ubuntu:Pro:FIPS:18.04:LTSlinux-aws-fips4.15.0-2000.4, 0
Ubuntu:18.04:LTSlinux-hwe-edge5.0.0-16.17~18.04.1, 5.0.0-17.18~18.04.1, 5.0.0-19.20~18.04.1
Ubuntu:16.04:LTSlinux-hwe-edge4.15.0-13.14~16.04.1, 4.15.0-15.16~16.04.1, 4.15.0-20.21~16.04.1
Ubuntu:Pro:14.04:LTSlinux3.13.0-63.103, 0, 3.11.0-12.19
Ubuntu:16.04:LTSlinux-azure4.15.0-1067.72, 4.15.0-1069.74, 4.15.0-1049.54
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1098.103, 4.4.0-1099.104, 4.4.0-1100.105
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1070.77, 4.15.0-1067.74, 4.15.0-1066.73
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-aws-fips4.15.0-2000.4, 0
Ubuntu:18.04:LTSlinux-azure-5.35.3.0-1007.8~18.04.1, 0
Ubuntu:18.04:LTSlinux-oracle-5.05.0.0-1008.13~18.04.1, 5.0.0-1007.12~18.04.1, 0
Ubuntu:18.04:LTSlinux-kvm4.15.0-1046.46, 4.15.0-1044.44, 4.15.0-1012.12
Ubuntu:18.04:LTSlinux-oem-osp15.0.0-1025.28, 5.0.0-1027.31, 5.0.0-1028.32
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1050.53, 4.15.0-1049.52, 4.15.0-1048.51
Ubuntu:20.04:LTSlinux-gke5.4.0-1097.104, 5.4.0-1039.41, 5.4.0-1037.39
Ubuntu:18.04:LTSlinux-azure-edge5.0.0-1012.12~18.04.2, 4.18.0-1008.8~18.04.1, 4.18.0-1007.7~18.04.1
Ubuntu:18.04:LTSlinux-aws-5.05.0.0-1022.25~18.04.1, 0, 5.0.0-1021.24~18.04.1
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1074.77+cvm1.1, 5.4.0-1076.79+cvm1.1, 5.4.0-1078.81+cvm1.1

…and 28 more

Timeline

References

Open in Interactive Console →