PT-2019-4484 · Linux+2 · Linux Kernel+2

Publicado

2019-06-21

·

Atualizado

2025-09-29

·

CVE-2019-19448

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.0.21 and 5.3.11
Description The issue is related to the use of memory after it has been freed in the try merge free space function of the Linux kernel, specifically in the fs/btrfs/free-space-cache.c file. This can be exploited by mounting a crafted btrfs filesystem image, performing certain operations, and then making a syncfs system call, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel version 5.0.21, update to a version that contains a fix for this issue. For Linux kernel version 5.3.11, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting the use of the btrfs filesystem until a patch is available.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2019-3180
ALT-PU-2019-3268
ALT-PU-2020-2659
ALT-PU-2020-2660
ALT-PU-2020-2695
ALT-PU-2020-2710
ALT-PU-2020-2726
ALT-PU-2020-2732
ALT-PU-2020-3057
ALT-PU-2021-1745
BDU:2020-00304
CVE-2019-19448
DLA-2385-1
DLA-2420-1
DLA-2420-2
ELSA-2020-5913
ELSA-2021-9459
MGASA-2020-0355
USN-4578-1

Produtos afetados

Alt Linux
Linux Kernel
Ubuntu