VDB

CVE-2019-15920

CVE-2019-15920 PUBLISHED

An issue was discovered in the Linux kernel before 5.0.10. SMB2_read in fs/cifs/smb2pdu.c has a use-after-free. NOTE: this was not fixed correctly in 5.0.10; see the 5.0.11 ChangeLog, which documents a memory leak.

EPSS 0.55% · 68.3th percentile

Risk Scores

EPSS Score
0.55%
68.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-hwe0, 4.18.0-14.15~18.04.1, 4.18.0-15.16~18.04.1
Ubuntu:18.04:LTSlinux-oem-osp15.0.0-1012.13, 5.0.0-1010.11, 0
Ubuntu:18.04:LTSlinux-hwe-edge5.3.0-22.24~18.04.1, 0, 5.0.0-16.17~18.04.1
Ubuntu:18.04:LTSlinux-azure4.15.0-1035.36, 4.15.0-1036.38, 4.15.0-1037.39

Timeline

  • Sep 4, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›