Nivaskumark / kernel_v4.19.72_old

Other
0 stars 0 forks source link

CVE-2019-19815 (Medium) detected in linuxlinux-4.19.83 #47

Open mend-bolt-for-github[bot] opened 2 years ago

mend-bolt-for-github[bot] commented 2 years ago

CVE-2019-19815 - Medium Severity Vulnerability

Vulnerable Library - linuxlinux-4.19.83

Apache Software Foundation (ASF)

Library home page: https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/?wsslib=linux

Found in HEAD commit: ce49083a1c14be2d13cb5e878257d293e6c748bc

Found in base branch: master

Vulnerable Source Files (2)

/include/trace/events/f2fs.h /include/trace/events/f2fs.h

Vulnerability Details

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.

Publish Date: 2019-12-17

URL: CVE-2019-19815

CVSS 3 Score Details (5.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19816

Release Date: 2019-12-17

Fix Resolution: v5.3-rc1


Step up your Open Source Security Game with Mend here

mend-bolt-for-github[bot] commented 2 years ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.