CVE-2019-9213: Canonical Ubuntu Linux

Medium severity, CVSS 5.5. EPSS: 5.7% chance of exploitation in the next 30 days.

In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: from 4.9, before 4.9.162 (fixed in 4.9.162); from 4.14, before 4.14.105 (fixed in 4.14.105); from 4.19, before 4.19.27 (fixed in 4.19.27); from 4.20, before 4.20.14 (fixed in 4.20.14)
  • Opensuse Leap: version 15.0 only; version 42.3 only
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only

Published 2019-03-05. Last modified 2026-06-17.