VDB

CVE-2019-16921

CVE-2019-16921 PUBLISHED

In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive information from kernel stack memory, aka CID-df7e40425813.

EPSS 0.27% · 50.9th percentile

Risk Scores

EPSS Score
0.27%
50.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlinux-lts-xenial0, 4.4.0-13.29~14.04.1, 4.4.0-14.30~14.04.2
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1002.2, 4.4.0-1009.9, 4.4.0-1010.10
Ubuntu:Pro:14.04:LTSlinux-azure*, 0, 4.15.0-1023.24~14.04.1
Ubuntu:Pro:14.04:LTSlinux3.13.0-139.188, 3.13.0-142.191, 3.13.0-143.192

Timeline

  • Sep 27, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›