CVE-2019-9453 PUBLISHED

In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

EPSS 0.04% · 10.6th percentile

Risk Scores

EPSS Score
0.04%
10.6th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1103.109+cvm1.1, 0, 5.4.0-1063.66+cvm2.2
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 0, 5.3.0-1007.8
Ubuntu:18.04:LTSlinux-kvm4.15.0-1019.19, 0, 4.15.0-1002.2
Ubuntu:18.04:LTSlinux-azure-edge5.0.0-1012.12~18.04.2, 4.18.0-1008.8~18.04.1, 4.18.0-1007.7~18.04.1
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-143.169~14.04.2, 4.4.0-42.62~14.04.1, 4.4.0-45.66~14.04.1
Ubuntu:16.04:LTSlinux-kvm4.4.0-1039.45, 4.4.0-1040.46, 4.4.0-1041.47
Ubuntu:18.04:LTSlinux-azure5.0.0-1032.34, 5.0.0-1036.38, 5.0.0-1035.37
Ubuntu:18.04:LTSlinux-hwe0, 4.18.0-13.14~18.04.1, 5.0.0-29.31~18.04.1
Ubuntu:18.04:LTSlinux-aws4.15.0-1025.25, 4.15.0-1027.27, 4.15.0-1029.30
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1026.29, 4.4.0-1030.33, 4.4.0-1032.36
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1004.5~18.04.1, 4.18.0-1011.12~18.04.1, 4.18.0-1012.13~18.04.1
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1032.34, 4.15.0-1030.32, 0
Ubuntu:18.04:LTSlinux-hwe-edge5.0.0-20.21~18.04.1, 5.0.0-19.20~18.04.1, 5.0.0-17.18~18.04.1
Ubuntu:18.04:LTSlinux4.15.0-39.42, 0, 4.13.0-16.19
Ubuntu:22.04:LTSlinux-riscv5.13.0-1004.4, 5.15.0-1008.8, 5.15.0-1011.12
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:18.04:LTSlinux-snapdragon4.4.0-1077.82, 4.4.0-1078.83, 4.4.0-1079.84
Ubuntu:20.04:LTSlinux-gke5.4.0-1054.57, 5.4.0-1053.56, 5.4.0-1052.55
Ubuntu:18.04:LTSlinux-aws-5.05.0.0-1027.30, 5.0.0-1025.28, 5.0.0-1024.27~18.04.1

…and 26 more

Timeline

References

Open in Interactive Console →