CVE-2019-9453

Description

In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

Risk Information

Base Score
4.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.036

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-4527-1) linux-image-aws_4.4.0.1114.119_amd64.debLinux
Linux kernel (USN-4527-1) linux-image-generic_4.4.0.190.196_i386.debLinux
Linux kernel (USN-4527-1) linux-image-generic_4.4.0.190.196_amd64.debLinux
Linux kernel (USN-4527-1) linux-image-virtual_4.4.0.190.196_i386.debLinux
Linux kernel (USN-4527-1) linux-image-virtual_4.4.0.190.196_amd64.debLinux
Linux kernel (USN-4527-1) linux-image-lowlatency_4.4.0.190.196_i386.debLinux
Linux kernel (USN-4527-1) linux-image-lowlatency_4.4.0.190.196_amd64.debLinux
Linux kernel (USN-4527-1) linux-image-4.4.0-1114-aws_4.4.0-1114.127_amd64.debLinux
Linux kernel (USN-4527-1) linux-image-4.4.0-190-generic_4.4.0-190.220_i386.debLinux
Linux kernel (USN-4527-1) linux-image-4.4.0-190-generic_4.4.0-190.220_amd64.debLinux
Linux kernel (USN-4527-1) linux-image-4.4.0-190-lowlatency_4.4.0-190.220_i386.debLinux
Linux kernel (USN-4527-1) linux-image-4.4.0-190-lowlatency_4.4.0-190.220_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234