HIGH
kernel: CIFS: Relative paths injection in directory entry lists
Published Nov 27, 2019
8.8
HIGHCVSS 3.1
EPSS 5.12%
Description
Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
Affected products
-
- Version kernel version 4.9.0StatusaffectedConstraints-
- Version
Configuration 1
OR
- ≥ 2.6.12 · < 3.16.81
- ≥ 3.17 · < 4.4.208
- ≥ 4.5 · < 4.9.208
- ≥ 4.10 · < 4.14.162
- ≥ 4.15 · < 4.19.93
- ≥ 4.20 · < 5.3.8
Configuration 2
- 8.0
Configuration 3
OR
- 18.04
- 19.04
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Under investigation
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Under investigation | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- https://access.redhat.com/security/cve/CVE-2019-10220 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1741727 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10220 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2233 Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10220
- https://security.netapp.com/advisory/ntap-20200103-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4226-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10220
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-10220 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1741727 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10220 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2233 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10220 | ||
| https://security.netapp.com/advisory/ntap-20200103-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://usn.ubuntu.com/4226-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-10220 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 27, 2019
Updated Aug 4, 2024
Reserved Mar 27, 2019
Link CVE-2019-10220
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-2233 Assigner redhat
Published Nov 27, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-2233