CVE-2019-15920: Linux Kernel

Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 5.0.10. SMB2_read in fs/cifs/smb2pdu.c has a use-after-free. NOTE: this was not fixed correctly in 5.0.10; see the 5.0.11 ChangeLog, which documents a memory leak.

Affected products

  • Linux Linux Kernel: before 5.0.10 (fixed in 5.0.10)
  • Opensuse Leap: version 15.0 only; version 15.1 only

Published 2019-09-04. Last modified 2026-06-17.