CVE-2019-19813
PoC —CVSS 3.1
5.5 medium
EPSS
2%p81
Published
()
Modified
Description
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/delayed-inode.c.
- Vendors
- linuxcanonicaldebiannetapp
- Products
- linux kernel, ubuntu linux, debian linux, active iq unified manager, data availability services, hci management node, solidfire, steelstore cloud integrated storage, aff a700s firmware, fas8300 firmware, fas8700 firmware, aff a400 firmware
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.