Back

MEDIUM

kernel: fs/ext4/extents.c leads to information disclosure

Published May 15, 2019

Description

fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.

Affected products

Remediation

Red Hat statement

This is a possible information leak of data that existed in the extent tree blocks. While the attacker does not have control of what exists in the blocks prior to this point they may be able to glean confidential information or possibly information that could be used to further another attack.

Weaknesses (1)

References (27)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published May 15, 2019
Updated Aug 4, 2024
Reserved May 9, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date May 11, 2019
Bugzilla 1712072

ENISA EUVD

Assigner mitre
Published May 15, 2019
Updated Aug 4, 2024

GitHub

No data