ZeroHour

CVE-2019-19813

PoC
CVSS 3.1
5.5 medium
EPSS
2%p81
Published
()
Modified
Description

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/delayed-inode.c.

Vendors
linuxcanonicaldebiannetapp
Products
linux kernel, ubuntu linux, debian linux, active iq unified manager, data availability services, hci management node, solidfire, steelstore cloud integrated storage, aff a700s firmware, fas8300 firmware, fas8700 firmware, aff a400 firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.