VulnerabilityModified
CVE-2019-5068
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2.
MEDIUM 4.4EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-277, CWE-732
- Affected
- mesa3d/mesa · opensuse/leap · debian/debian linux · canonical/ubuntu linux
- Source
- talos-cna@cisco.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00037.htmlMailing List, Third Party Advisory
- https://gitlab.freedesktop.org/mesa/mesa/-/commit/02c3dad0f3b4d26e0faa5cc51d06bc50d693dcdcPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00013.htmlMailing List, Third Party Advisory
- https://lists.freedesktop.org/pipermail/mesa-dev/2019-October/223704.htmlMailing List, Patch, Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857Exploit, Third Party Advisory
- https://usn.ubuntu.com/4271-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00037.htmlMailing List, Third Party Advisory
- https://gitlab.freedesktop.org/mesa/mesa/-/commit/02c3dad0f3b4d26e0faa5cc51d06bc50d693dcdcPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00013.htmlMailing List, Third Party Advisory
- https://lists.freedesktop.org/pipermail/mesa-dev/2019-October/223704.htmlMailing List, Patch, Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857Exploit, Third Party Advisory
- https://usn.ubuntu.com/4271-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.