CVE-2019-25160

Source
https://cve.org/CVERecord?id=CVE-2019-25160
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-25160.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-25160
Downstream
Related
Published
2024-02-26T18:15:06.930Z
Modified
2026-02-21T01:12:02.198121Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

netlabel: fix out-of-bounds memory accesses

There are two array out-of-bounds memory accesses, one in cipsov4maplvlvalid(), the other in netlblbitmapwalk(). Both errors are embarassingly simple, and the fixes are straightforward.

As a FYI for anyone backporting this patch to kernels prior to v4.8, you'll want to apply the netlblbitmapwalk() patch to cipsov4bitmapwalk() as netlblbitmap_walk() doesn't exist before Linux v4.8.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
24fbbeb15685f23ae63c1bffaa7868426e687a9e
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
6a31767f84ad31445865f1297d49937319f775c3
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
6b50202a4d53bf527c640467bcff68b50a5e38a2
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
a5073cb787160a3f852be1c380fe7f929d5c944f
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
d9896164529697fade02aafc65a06722f7191d68
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
f4a652885326ba8148e742a0f2a5fc2ef4140711
Introduced
c3fe6924620fd733ffe8bc8a9da1e9cde08402b3
Fixed
0e3910b9b93147bb89eededfebe7bddb3826aa6e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-25160.json"