ZeroHour

CVE-2019-19318

PoC
CVSS 3.1
4.4 medium
EPSS
<1%p49
Published
()
Modified
Description

In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,

Vendors
linuxopensusecanonicaldebiannetapp
Products
linux kernel, leap, ubuntu linux, debian linux, active iq unified manager, data availability services, hci management node, solidfire, steelstore cloud integrated storage, aff a700s firmware, fas8300 firmware, fas8700 firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.