Vulnerability Description
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 5.1.2 |
| Fedoraproject | Fedora | 29 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Eus | 8.1 |
| Redhat | Enterprise Linux For Real Time | 7 |
| Redhat | Enterprise Linux For Real Time For Nfv | 7 |
| Redhat | Enterprise Linux For Real Time For Nfv Tus | 8.2 |
| Redhat | Enterprise Linux For Real Time Tus | 8.2 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 8.2 |
| Redhat | Enterprise Linux Server Tus | 8.2 |
| Redhat | Enterprise Linux Workstation | 7.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00071.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.htmlBroken Link
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/108372Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2029Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2043Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3309Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3517Third Party Advisory
- https://github.com/torvalds/linux/commit/592acbf16821288ecdc4192c47e3774a4c48bb6PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00010.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00011.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2019/Jun/26Mailing ListThird Party Advisory
- https://usn.ubuntu.com/4068-1/Third Party Advisory
FAQ
What is CVE-2019-11833?
CVE-2019-11833 is a vulnerability with a CVSS score of 5.5 (MEDIUM). fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninit...
How severe is CVE-2019-11833?
CVE-2019-11833 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11833?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Debian Debian Linux, Canonical Ubuntu Linux, Redhat Enterprise Linux.