CVE

CVE-2019-25160

Severity:
HIGH
Type:
CWE-125 Out-of-bounds Read
Publication date:
26/02/2024
Last modified:
17/04/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netlabel: fix out-of-bounds memory accesses<br /> <br /> There are two array out-of-bounds memory accesses, one in<br /> cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both<br /> errors are embarassingly simple, and the fixes are straightforward.<br /> <br /> As a FYI for anyone backporting this patch to kernels prior to v4.8,<br /> you&amp;#39;ll want to apply the netlbl_bitmap_walk() patch to<br /> cipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn&amp;#39;t exist before<br /> Linux v4.8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.19 (including) 3.16.66 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.17.0 (including) 3.18.137 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.19.0 (including) 4.4.177 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.5.0 (including) 4.9.163 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.10.0 (including) 4.14.106 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15.0 (including) 4.19.28 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20.0 (including) 4.20.15 (excluding)