Oval Definition:oval:com.ubuntu.xenial:def:2019197670000000
Revision Date:2019-12-12Version:1
Title:CVE-2019-19767 on Ubuntu 16.04 LTS (xenial) - low.
Description:The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163. It was discovered that the ext4 file system implementation in the Linux kernel did not properly handle certain conditions. An attacker could use this to specially craft an ext4 file system that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-19767
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • linux package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-16.19').
  • OR linux-aws package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1001.10').
  • OR linux-aws-hwe package in xenial was vulnerable but has been fixed (note: '4.15.0-1060.62~16.04.1').
  • OR linux-azure package in xenial was vulnerable but has been fixed (note: '4.15.0-1071.76').
  • OR linux-gcp package in xenial was vulnerable but has been fixed (note: '4.15.0-1055.59').
  • OR linux-hwe package in xenial was vulnerable but has been fixed (note: '4.15.0-88.88~16.04.1').
  • OR linux-kvm package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1004.9').
  • OR linux-meta package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-16.19').
  • OR linux-meta-aws package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1001.10').
  • OR linux-meta-aws-hwe package in xenial was vulnerable but has been fixed (note: '4.15.0-1060.62~16.04.1').
  • OR linux-meta-azure package in xenial was vulnerable but has been fixed (note: '4.15.0-1071.76').
  • OR linux-meta-gcp package in xenial was vulnerable but has been fixed (note: '4.15.0-1055.59').
  • OR linux-meta-hwe package in xenial was vulnerable but has been fixed (note: '4.15.0-88.88~16.04.1').
  • OR linux-meta-kvm package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1004.9').
  • OR linux-meta-oracle package in xenial was vulnerable but has been fixed (note: '4.15.0-1033.36~16.04.1').
  • OR linux-meta-raspi2 package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-1013.19').
  • OR linux-meta-snapdragon package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1012.12').
  • OR linux-oem: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'was needs-triage now end-of-life').
  • OR linux-oracle package in xenial was vulnerable but has been fixed (note: '4.15.0-1033.36~16.04.1').
  • OR linux-raspi2 package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-1013.19').
  • OR linux-signed package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-16.19').
  • OR linux-signed-azure package in xenial was vulnerable but has been fixed (note: '4.15.0-1071.76').
  • OR linux-signed-gcp package in xenial was vulnerable but has been fixed (note: '4.15.0-1055.59').
  • OR linux-signed-hwe package in xenial was vulnerable but has been fixed (note: '4.15.0-88.88~16.04.1').
  • OR linux-signed-oracle package in xenial was vulnerable but has been fixed (note: '4.15.0-1033.36~16.04.1').
  • OR linux-snapdragon package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1012.12').
  • BACK