PT-2019-4484 · Linux+2 · Linux Kernel+2
Publicado
2019-06-21
·
Atualizado
2025-09-29
·
CVE-2019-19448
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.0.21 and 5.3.11
Description
The issue is related to the use of memory after it has been freed in the try merge free space function of the Linux kernel, specifically in the fs/btrfs/free-space-cache.c file. This can be exploited by mounting a crafted btrfs filesystem image, performing certain operations, and then making a syncfs system call, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
For Linux kernel version 5.0.21, update to a version that contains a fix for this issue.
For Linux kernel version 5.3.11, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting the use of the btrfs filesystem until a patch is available.
Exploit
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel
Ubuntu