CVE-2019-15918: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely updated after a change from smb30 to smb21.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
- Linux Linux Kernel: from 4.13.5, before 4.14.166 (fixed in 4.14.166); from 4.15, before 4.19.73 (fixed in 4.19.73); from 4.20, before 5.0.10 (fixed in 5.0.10)
Published 2019-09-04. Last modified 2026-06-17.