CVE-2019-20367: Critical severity Freedesktop Libbsd vulnerability
Published Jan 8, 2020
·Updated
Last updated 25 August 2025
Other sources
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
— Launchpad
Affected Software
9 affected componentsFixes available
Freedesktop Libbsd<0.10.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
openSUSE Leap=15.1
debian/libbsd
0.11.3-1+deb11u10.11.7-20.12.2-20.12.2-3
Remediation
Event History
Jan 8, 2020
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·04:36 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·04:37 PM
Description
Jun 4, 2026
Data Sourced
via Debian·03:44 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-20367.
2
What is the severity of CVE-2019-20367?
The severity of CVE-2019-20367 is critical with a score of 9.1.
3
What is the description of CVE-2019-20367?
CVE-2019-20367 is an out-of-bounds read vulnerability in libbsd before version 0.10.0.
4
How does CVE-2019-20367 affect the affected software?
CVE-2019-20367 affects libbsd versions 0.9.1-2+deb10u1, 0.11.3-1+deb11u1, 0.11.7-2, 0.11.7-4, 0.8.7-1ubuntu0.1, 0.9.1-2ubuntu0.1, 0.6.0-2ubuntu1+, 0.10.0-1, and 0.8.2-1ubuntu0.1.
5
How can I fix CVE-2019-20367?
To fix CVE-2019-20367, you should update libbsd to version 0.10.0 or higher, as it has been patched to address this vulnerability.