Description
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:HExploitability: 0.8 | Impact: 5.2Attack Vector: Local
Complexity: Low
Privileges: High
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: High
Affected Packages4 packages
🔴Vulnerability Details
2GHSAGHSA-wwjm-g2hc-3mhm: In the Linux kernel 5↗2022-05-24 ▶ OSVCVE-2019-19927: In the Linux kernel 5↗2019-12-31 ▶ 📋Vendor Advisories
2Red Hatkernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c↗2019-12-31 ▶ DebianCVE-2019-19927: linux - In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubun...↗2019 ▶ 📄Research Papers
1arXivReposVul: A Repository-Level High-Quality Vulnerability Dataset↗2024-02-08 ▶ 💬Community
2BugzillaCVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c↗2020-01-11 ▶ BugzillaCVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c [fedora-all]↗2020-01-11 ▶