CVE-2019-9637: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 7.3% chance of exploitation in the next 30 days.
An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Netapp Storage Automation Store: affected versions not specified
- Opensuse Leap: version 42.3 only
- PHP PHP: before 7.1.27 (fixed in 7.1.27); from 7.2.0, before 7.2.16 (fixed in 7.2.16); from 7.3.0, before 7.3.3 (fixed in 7.3.3)
Published 2019-03-09. Last modified 2026-06-17.