Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jungyeon

#39866de 53,633
6.8CVSS total
Vulnerabilidades · 1
PT-2019-4692
6.8
2019-04-09
Linux · Linux Kernel · CVE-2019-19319
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 5.2 **Description** The issue is related to a use-after-free in the `ext4 xattr set entry` function in `fs/ext4/xattr.c`, which can cause a slab-out-of-bounds write access. This can occur when a large `old size` value is used in a `memset` call after mounting a crafted ext4 image. The exploitation of this issue may allow a remote attacker to execute arbitrary code. **Recommendations** For Linux kernel versions prior to 5.2, update to version 5.2 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.