CVE-2019-25160 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both errors are embarassingly simple, and the fixes are straightforward. As a FYI for anyone backporting this patch to kernels prior to v4.8, you'll want to apply the netlbl_bitmap_walk() patch to cipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before Linux v4.8.

EPSS 0.01% · 2.4th percentile

Risk Scores

EPSS Score
0.01%
2.4th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-oem-6.16.1.0-1016.16, 0, 6.1.0-1004.4
Ubuntu:22.04:LTSlinux-starfive-5.195.19.0-1019.21~22.04.1, 5.19.0-1020.22~22.04.1, 0
Ubuntu:22.04:LTSlinux-azure-6.26.2.0-1014.14~22.04.1, 6.2.0-1012.12~22.04.1, 6.2.0-1011.11~22.04.1
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:20.04:LTSlinux-riscv-5.115.11.0-1026.28~20.04.1, 0, 5.11.0-1015.16~20.04.1
Ubuntu:20.04:LTSlinux-oem-5.145.14.0-1024.26, 5.14.0-1013.13, 5.14.0-1018.19
Ubuntu:Pro:FIPS:18.04:LTSlinux-azure-fips0, 4.15.0-1002.2
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-aws-fips4.15.0-2000.4, 0
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:22.04:LTSlinux-riscv-5.195.19.0-1018.19~22.04.1, 5.19.0-1017.18~22.04.1, 0
Ubuntu:18.04:LTSlinux-gcp4.15.0-1006.6, 4.15.0-1009.9, 4.15.0-1010.10
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1046.50~14.04.1, 0, 4.15.0-1023.24~14.04.1
Ubuntu:20.04:LTSlinux-hwe-5.135.13.0-52.59~20.04.1, 5.13.0-51.58~20.04.1, 5.13.0-48.54~20.04.1
Ubuntu:Pro:14.04:LTSlinux3.13.0-65.105, 3.13.0-65.106, 3.13.0-66.108
Ubuntu:16.04:LTSlinux-oracle4.15.0-1018.20~16.04.1, 0, 4.15.0-1007.9~16.04.1
Ubuntu:20.04:LTSlinux-aws-5.115.11.0-1023.24~20.04.1, 5.11.0-1025.27~20.04.1, 5.11.0-1017.18~20.04.1
Ubuntu:18.04:LTSlinux-gke-5.45.4.0-1035.37~18.04.1, 0, 5.4.0-1025.25~18.04.1
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1032.34~16.04.1, 4.15.0-1033.35~16.04.1, 4.15.0-1035.37~16.04.1
Ubuntu:22.04:LTSlinux-aws-5.195.19.0-1024.25~22.04.1, 5.19.0-1022.23~22.04.1, 5.19.0-1020.21~22.04.1
Ubuntu:16.04:LTSlinux4.4.0-119.143, 4.4.0-121.145, 4.4.0-122.146

…and 68 more

Timeline

References

Open in Interactive Console →