CVE-2019-5068
published 2019-11-05CVE-2019-5068: An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared…
PriorityP418medium4.4CVSS 3.1
AVLACLPRLUINSUCLILAN
EPSS
0.48%
38.5th percentile
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | mesa | < mesa 19.2.6-1 (bookworm) | mesa 19.2.6-1 (bookworm) |
| mesa3d | mesa | — | — |
| mesa3d | mesa | >= 0 < 19.2.6-1 | 19.2.6-1 |
| mesa3d | mesa | >= 0 < 19.2.6-1 | 19.2.6-1 |
| mesa3d | mesa | >= 0 < 19.2.6-1 | 19.2.6-1 |
| mesa3d | mesa | >= 0 < 19.2.6-1 | 19.2.6-1 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv4.4MEDIUM
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rrg9-xrw3-h9vv: An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19
ghsa_unreviewed·2022-05-24
CVE-2019-5068 [MEDIUM] CWE-277 GHSA-rrg9-xrw3-h9vv: An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
OSV
CVE-2019-5068: An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19
osv·2019-11-05·CVSS 4.4
CVE-2019-5068 [MEDIUM] CVE-2019-5068: An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
Ubuntu
Mesa vulnerability
vendor_ubuntu·2020-02-06
CVE-2019-5068 Mesa vulnerability
Title: Mesa vulnerability
Summary: Mesa could be made to expose sensitive information.
Tim Brown discovered that Mesa incorrectly handled shared memory
permissions. A local attacker could use this issue to obtain and possibly
alter sensitive information belonging to another user.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
mesa: security bypass in 3D library graphics
vendor_redhat·2019-10-23·CVSS 4.4
CVE-2019-5068 [MEDIUM] CWE-732 mesa: security bypass in 3D library graphics
mesa: security bypass in 3D library graphics
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
Package: mesa (Red Hat Enterprise Linux 5) - Out of support scope
Package: mesa (Red Hat Enterprise Linux 6) - Out of support scope
Package: mesa (Red Hat Enterprise Linux 7) - Will not fix
Package: mesa (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2019-5068: mesa - An exploitable shared memory permissions vulnerability exists in the functionali...
vendor_debian·2019·CVSS 4.4
CVE-2019-5068 [MEDIUM] CVE-2019-5068: mesa - An exploitable shared memory permissions vulnerability exists in the functionali...
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 19.2.6-1)
bullseye: resolved (fixed in 19.2.6-1)
forky: resolved (fixed in 19.2.6-1)
sid: resolved (fixed in 19.2.6-1)
trixie: resolved (fixed in 19.2.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5068 mesa: security bypass in 3D library graphics [fedora-all]
bugzilla·2019-11-08·CVSS 4.4
CVE-2019-5068 [MEDIUM] CVE-2019-5068 mesa: security bypass in 3D library graphics [fedora-all]
CVE-2019-5068 mesa: security bypass in 3D library graphics [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2019-5068 mesa: security bypass in 3D library graphics
bugzilla·2019-11-08·CVSS 4.4
CVE-2019-5068 [MEDIUM] CVE-2019-5068 mesa: security bypass in 3D library graphics
CVE-2019-5068 mesa: security bypass in 3D library graphics
An exploitable shared memory permissions vulnerability exists in the
functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the
shared memory without any specific permissions to trigger this vulnerability.
Reference:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857
Discussion:
Created mesa tracking bugs for this issue:
Affects: fedora-all [bug 1770096]
---
Upstream bug: https://gitlab.freedesktop.org/mesa/mesa/issues/121
Upstream patch: https://gitlab.freedesktop.org/mesa/mesa/commit/ddc7d7a33b36c2305955bbffb1f295196c1a9669
---
External References:
https://www.mesa3d.org/relnotes/19.1.8.html
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00037.htmlhttps://gitlab.freedesktop.org/mesa/mesa/-/commit/02c3dad0f3b4d26e0faa5cc51d06bc50d693dcdchttps://lists.debian.org/debian-lts-announce/2019/11/msg00013.htmlhttps://lists.freedesktop.org/pipermail/mesa-dev/2019-October/223704.htmlhttps://talosintelligence.com/vulnerability_reports/TALOS-2019-0857https://usn.ubuntu.com/4271-1/http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00037.htmlhttps://gitlab.freedesktop.org/mesa/mesa/-/commit/02c3dad0f3b4d26e0faa5cc51d06bc50d693dcdchttps://lists.debian.org/debian-lts-announce/2019/11/msg00013.htmlhttps://lists.freedesktop.org/pipermail/mesa-dev/2019-October/223704.htmlhttps://talosintelligence.com/vulnerability_reports/TALOS-2019-0857https://usn.ubuntu.com/4271-1/
2019-11-05
Published