Bug 1134853 - (CVE-2019-11059) VUL-1: CVE-2019-11059: u-boot: mishandling the ext4 64-bit extension, resulting in a buffer overflow
(CVE-2019-11059)
VUL-1: CVE-2019-11059: u-boot: mishandling the ext4 64-bit extension, resulti...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/232535/
CVSSv3:SUSE:CVE-2019-11059:5.1:(AV:L/...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-05-13 11:05 UTC by Robert Frohl
Modified: 2021-01-27 17:08 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2019-05-13 11:05:00 UTC
CVE-2019-11059

Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension,
resulting in a buffer overflow.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-11059
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11059
https://git.denx.de/?p=u-boot.git;a=commit;h=febbc583319b567fe3d83e521cc2ace9be8d1501
https://github.com/u-boot/u-boot/commits/master
Comment 1 Robert Frohl 2019-05-13 11:16:22 UTC
tracking all codestreams as affected:
- SUSE:SLE-12-SP3:Update
- SUSE:SLE-12-SP4:Update
- SUSE:SLE-15:Update
Comment 2 Robert Frohl 2019-05-13 11:30:06 UTC
Concerning SUSE:SLE-12-SP3:Update:

This might not be vulnerable if we go by the affected version, but the code looks like it could be vulnerable too.

@Matthias: Please let us know if my assessment was incorrect and I can adjust our tracking.
Comment 6 Swamp Workflow Management 2020-11-09 14:15:11 UTC
SUSE-SU-2020:3256-1: An update that fixes 20 vulnerabilities is now available.

Category: security (important)
Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1144656,1144675,1162198,1167209
CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-13104,CVE-2019-13106,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    u-boot-2018.03-4.3.1, u-boot-rpi3-2018.03-4.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2020-11-09 14:23:43 UTC
SUSE-SU-2020:3255-1: An update that solves 18 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1160566,1162198,1167209
CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    u-boot-2019.01-5.3.1, u-boot-rpi3-2019.01-5.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2020-11-11 14:27:40 UTC
SUSE-SU-2020:3282-1: An update that fixes 18 vulnerabilities is now available.

Category: security (important)
Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1162198,1167209
CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    u-boot-2019.01-7.10.1, u-boot-rpi3-2019.01-7.10.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2020-11-11 14:43:54 UTC
SUSE-SU-2020:3283-1: An update that solves 18 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1098447,1098649,1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1162198,1167209
CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15 (src):    u-boot-2018.03-4.6.1
SUSE Linux Enterprise Server 15-LTSS (src):    u-boot-2018.03-4.6.1, u-boot-rpi3-2018.03-4.6.2
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    u-boot-2018.03-4.6.1, u-boot-rpi3-2018.03-4.6.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    u-boot-2018.03-4.6.1, u-boot-rpi3-2018.03-4.6.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2020-11-15 20:16:33 UTC
openSUSE-SU-2020:1930-1: An update that fixes 18 vulnerabilities is now available.

Category: security (important)
Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1162198,1167209
CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14199,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2020-10648,CVE-2020-8432
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    u-boot-2019.01-lp151.6.13.1
Comment 11 Swamp Workflow Management 2020-11-21 11:17:21 UTC
SUSE-SU-2020:3474-1: An update that fixes 17 vulnerabilities is now available.

Category: security (important)
Bug References: 1134157,1134853,1143463,1143777,1143817,1143818,1143819,1143820,1143821,1143823,1143824,1143825,1143827,1143828,1143830,1143831,1167209
CVE References: CVE-2019-11059,CVE-2019-11690,CVE-2019-13103,CVE-2019-14192,CVE-2019-14193,CVE-2019-14194,CVE-2019-14195,CVE-2019-14196,CVE-2019-14197,CVE-2019-14198,CVE-2019-14200,CVE-2019-14201,CVE-2019-14202,CVE-2019-14203,CVE-2019-14204,CVE-2019-14299,CVE-2020-10648
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    u-boot-2016.07-12.3.1, u-boot-rpi3-2016.07-12.3.1
SUSE Enterprise Storage 5 (src):    u-boot-2016.07-12.3.1, u-boot-rpi3-2016.07-12.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Alexandros Toptsoglou 2021-01-27 17:08:32 UTC
DONE