CVE-2019-19927
published 2019-12-31CVE-2019-19927: In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some…
PriorityP425medium6CVSS 3.1
AVLACLPRHUINSUCHINAH
EPSS
0.75%
51.4th percentile
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.2.6-1 (bookworm) | linux 5.2.6-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wwjm-g2hc-3mhm: In the Linux kernel 5
ghsa_unreviewed·2022-05-24
CVE-2019-19927 [LOW] GHSA-wwjm-g2hc-3mhm: In the Linux kernel 5
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module.
OSV
CVE-2019-19927: In the Linux kernel 5
osv·2019-12-31·CVSS 6.0
CVE-2019-19927 [MEDIUM] CVE-2019-19927: In the Linux kernel 5
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module.
Red Hat
kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c
vendor_redhat·2019-12-31·CVSS 6.0
CVE-2019-19927 [MEDIUM] CWE-125 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c
kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module.
An out-of-bounds (OOB) memory access flaw was found in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c in the Linux kernel’s graphics module. Incrementing the page pointer for huge pages was not in sync with the reference counter, and this could lead to an out-of-bounds access or a denial of service. This flaw allows a local attacker with special user privileges (or root) to cause memory exploitation.
Mit
Debian
CVE-2019-19927: linux - In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubun...
vendor_debian·2019·CVSS 6.0
CVE-2019-19927 [MEDIUM] CVE-2019-19927: linux - In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubun...
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c
bugzilla·2020-01-11·CVSS 6.0
CVE-2019-19927 [MEDIUM] CVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c
CVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c
A out-of-bounds (OOB) memory access flaw was found in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c in Linux kernel graphics module. Here incrementing the page pointer for huge pages was not in sync with the reference counter, and this could lead to an out-of-bound memory problem or a DoS. A local attacker with special user privilege (or root) can plot an exploit in the memory to harm.
References:
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19927
Upstream patch:
https://github.com/torvalds/linux/commit/453393369dc9806d2455151e329c599684762428
https://github.com/torvalds/linux/commit/a66477b0efe511d98dde3e4aaeb189790e6f0a39
https://github.com/torvalds/linux/commit/ac1e516d5a4c56
Bugzilla
CVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c [fedora-all]
bugzilla·2020-01-11·CVSS 6.0
CVE-2019-19927 [MEDIUM] CVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c [fedora-all]
CVE-2019-19927 kernel: Out-of-bounds read in ttm_put_pages in gpu/drm/ttm/ttm_page_alloc.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
arXiv
ReposVul: A Repository-Level High-Quality Vulnerability Dataset
arxiv_fulltext·2024-02-08
ReposVul: A Repository-Level High-Quality Vulnerability Dataset
: A Repository-Level High-Quality Vulnerability Dataset
Xinchen Wang^
Harbin Institute of Technology,
Shenzhen
China
[email protected]
Ruida Hu^
Harbin Institute of Technology,
Shenzhen
China
[email protected]
Cuiyun Gao^
Harbin Institute of Technology,
Shenzhen
China
[email protected]
Xin-Cheng Wen
Harbin Institute of Technology,
Shenzhen
China
[email protected]
Yujia Chen
Harbin Institute of Technology,
Shenzhen
China
[email protected]
Qing Liao
Harbin Institute of Technology,
Shenzhen
China
[email protected]
^ These authors contribute to the work equally and are co-first authors of the paper.
^ Corresponding author. The author is also affiliated with Peng Cheng Laboratory and Guangdong Provincial Key Laboratory of Novel Security Intelligence T
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.htmlhttps://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19927https://github.com/torvalds/linux/commit/453393369dc9806d2455151e329c599684762428https://github.com/torvalds/linux/commit/a66477b0efe511d98dde3e4aaeb189790e6f0a39https://github.com/torvalds/linux/commit/ac1e516d5a4c56bf0cb4a3dfc0672f689131cfd4https://security.netapp.com/advisory/ntap-20200204-0002/http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.htmlhttps://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19927https://github.com/torvalds/linux/commit/453393369dc9806d2455151e329c599684762428https://github.com/torvalds/linux/commit/a66477b0efe511d98dde3e4aaeb189790e6f0a39https://github.com/torvalds/linux/commit/ac1e516d5a4c56bf0cb4a3dfc0672f689131cfd4https://security.netapp.com/advisory/ntap-20200204-0002/
2019-12-31
Published