Path traversal in Linux kernel - CVE-2019-10220
Published: November 27, 2019 / Updated: August 8, 2020
Vulnerability identifier: #VU35028
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10220
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
Affected software
Linux kernel
RSA Authentication Manager
Dell EMC Data Protection Search
RSA Authentication Manager
Dell EMC Data Protection Search
How to mitigate CVE-2019-10220
Install update from vendor's website.
RSA Authentication Manager - update to 8.4 Patch 9
Dell EMC Data Protection Search - update to 19.3.0
Dell EMC Data Protection Search - update to 19.3.0