CVE-2019-10220: Path Traversal
Last updated 25 April 2025
Other sources
Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2019-10220?
CVE-2019-10220 can lead to unauthorized access or manipulation of directory entry lists due to relative path injection.
Which versions of the Linux kernel are affected by CVE-2019-10220?
CVE-2019-10220 affects Linux kernel versions between 2.6.12 and 5.3.8, along with specific versions of Debian and Ubuntu Linux.
How can I remediate CVE-2019-10220?
To fix CVE-2019-10220, upgrade the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
What types of systems are typically vulnerable to CVE-2019-10220?
Systems running affected versions of the Linux kernel, particularly those using CIFS for file sharing, are vulnerable to CVE-2019-10220.
Is CVE-2019-10220 a confirmed vulnerability?
Yes, CVE-2019-10220 has been officially documented and recognized as a vulnerability affecting the Linux CIFS implementation.