VDB
CVE-2019-19815
CVE-2019-19815
PUBLISHED
CVSS 5.5 MEDIUM
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.
EPSS 2.10% · 80.3th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
2.10%
80.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:FIPS:18.04:LTS | linux-gcp-fips | 0, 4.15.0-1001.1 |
| Ubuntu:Pro:18.04:LTS | linux-oracle | 4.15.0-1122.133, 4.15.0-1010.12, 4.15.0-1054.58 |
| Ubuntu:Pro:18.04:LTS | linux-azure-4.15 | 4.15.0-1179.194, 4.15.0-1177.192, 4.15.0-1176.191 |
| Ubuntu:Pro:16.04:LTS | linux-aws | 4.4.0-1032.41, 4.4.0-1128.142, 4.4.0-1129.143 |
| Ubuntu:16.04:LTS | linux-hwe-edge | 4.11.0-13.19~16.04.1, 0, * |
| Ubuntu:Pro:18.04:LTS | linux-gcp-4.15 | 4.15.0-1159.176, 4.15.0-1158.175, 4.15.0-1157.174 |
| Ubuntu:18.04:LTS | linux-hwe-edge | 0, *, 5.0.0-19.20~18.04.1 |
| Ubuntu:Pro:16.04:LTS | linux-oracle | 4.15.0-1051.55~16.04.1, 0, 4.15.0-1007.9~16.04.1 |
| Ubuntu:18.04:LTS | linux-hwe | 0, 4.18.0-14.15~18.04.1, 4.18.0-15.16~18.04.1 |
| Ubuntu:Pro:FIPS-updates:18.04:LTS | linux-gcp-fips | 4.15.0-2024.26, 4.15.0-2052.57, 4.15.0-2013.14 |
| Ubuntu:Pro:16.04:LTS | linux-azure | *, 4.15.0-1075.80, 4.15.0-1056.61 |
| Ubuntu:Pro:14.04:LTS | linux-azure | *, 4.15.0-1095.105~14.04.1, 4.15.0-1092.102~14.04.1 |
| Ubuntu:18.04:LTS | linux-oem | 0, 4.15.0-1002.3, 4.15.0-1006.9 |
| Ubuntu:Pro:FIPS:16.04:LTS | linux-fips | 4.4.0-1011.14, 4.4.0-1003.3, 4.4.0-1005.5 |
| Ubuntu:Pro:18.04:LTS | linux-aws | 4.15.0-1079.83, 4.15.0-1077.81, 4.15.0-1032.34 |
| Ubuntu:Pro:16.04:LTS | linux-hwe | 4.15.0-132.136~16.04.1, 4.15.0-133.137~16.04.1, 4.15.0-136.140~16.04.1 |
| Ubuntu:Pro:18.04:LTS | linux | 4.15.0-66.75, 4.15.0-221.232, 4.15.0-132.136 |
| Ubuntu:Pro:16.04:LTS | linux-kvm | 4.4.0-1129.139, 0, 4.4.0-1004.9 |
| Ubuntu:Pro:16.04:LTS | linux-aws-hwe | 4.15.0-1164.177~16.04.1, 0, 4.15.0-1030.31~16.04.1 |
| Ubuntu:Pro:14.04:LTS | linux-aws | 4.4.0-1147.153, 4.4.0-1149.155, 4.4.0-1150.156 |
…and 20 more
Timeline
- Dec 17, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-19815 third-party-advisory
- https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19815 third-party-advisory
- https://github.com/torvalds/linux/commit/4969c06a0d83c9c3dc50b8efcdc8eeedfce896f6#diff-41a7fa4590d2af87e82101f2b4dadb56 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19815 third-party-advisory