CVE-2019-10220: Canonical Ubuntu Linux
High severity, CVSS 8.8. EPSS: 5.1% chance of exploitation in the next 30 days.
Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 19.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: from 2.6.12, before 3.16.81 (fixed in 3.16.81); from 3.17, before 4.4.208 (fixed in 4.4.208); from 4.5, before 4.9.208 (fixed in 4.9.208); from 4.10, before 4.14.162 (fixed in 4.14.162); from 4.15, before 4.19.93 (fixed in 4.19.93); from 4.20, before 5.3.8 (fixed in 5.3.8)
Published 2019-11-27. Last modified 2026-06-17.