CVE-2019-19319
Public on 2019-11-27
Modified on 2020-06-03
Description
An out-of-bounds write flaw was found in the Linux kernel’s Ext4 FileSystem in the way it uses a crafted ext4 image. This flaw allows a local user with physical access to crash the system or potentially escalate their privileges on the system.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | kernel | 2020-06-03 | ALAS-2020-1377 | Fixed |
Amazon Linux 2 - Core | kernel | 2020-06-03 | ALAS2-2020-1431 | Fixed |
Amazon Linux 2 - Livepatch Extra | kernel-livepatch-4.14.173-137.228 | 2020-06-17 | ALAS2LIVEPATCH-2020-020 | Fixed |
Amazon Linux 2 - Livepatch Extra | kernel-livepatch-4.14.173-137.229 | 2020-06-17 | ALAS2LIVEPATCH-2020-019 | Fixed |
Amazon Linux 2 - Livepatch Extra | kernel-livepatch-4.14.177-139.253 | 2020-06-17 | ALAS2LIVEPATCH-2020-018 | Fixed |
Amazon Linux 2 - Livepatch Extra | kernel-livepatch-4.14.177-139.254 | 2020-06-17 | ALAS2LIVEPATCH-2020-017 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
NVD | CVSSv3 | 6.5 | CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
NVD | CVSSv2 | 4.4 | AV:L/AC:M/Au:N/C:P/I:P/A:P |