CVE-2019-5068
Publication date 5 November 2019
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mesa | ||
| 18.04 LTS bionic |
Fixed 19.2.8-0ubuntu0~18.04.2
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Notes
sbeattie
mesa and its build dependencies have been updated for the HWE stack in bionic, so to fix this there will require no-change rebuilds in the security pocket for libdrm, libclc, wayland, and llvm-toolchain-9.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | Low |
| Integrity impact | Low |
| Availability impact | None |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-4271-1
- Mesa vulnerability
- 6 February 2020