PT-2019-6223 · Linux+4 · Linux Kernel+4

Publicado

2019-06-21

·

Atualizado

2025-09-29

·

CVE-2019-19377

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 5.0.21
Description The issue is related to a use-after-free vulnerability in the btrfs queue work function, located in the fs/btrfs/async-thread.c file. This vulnerability can be exploited by mounting a crafted btrfs filesystem image, performing certain operations, and then unmounting it. The exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel version 5.0.21, consider applying a patch or updating to a newer version that addresses this issue. As a temporary workaround, restrict access to the btrfs queue work function in the fs/btrfs/async-thread.c file to minimize the risk of exploitation. Avoid mounting crafted btrfs filesystem images and performing operations that may trigger the use-after-free vulnerability until a patch is available.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2020-1849
ALT-PU-2020-1850
ALT-PU-2020-1851
ALT-PU-2020-1905
ALT-PU-2020-1945
ALT-PU-2020-2164
ALT-PU-2020-3057
ALT-PU-2021-1745
BDU:2022-05179
CVE-2019-19377
DLA-2483-1
ELSA-2020-5714
ELSA-2020-5913
ELSA-2022-10065
MGASA-2020-0183
MGASA-2020-0184
OPENSUSE-SU-2022:2177-1
OPENSUSE-SU-2022_2078-1
OPENSUSE-SU-2022_2079-1
OPENSUSE-SU-2022_2111-1
SUSE-SU-2022:2077-1
SUSE-SU-2022:2078-1
SUSE-SU-2022:2079-1
SUSE-SU-2022:2080-1
SUSE-SU-2022:2082-1
SUSE-SU-2022:2103-1
SUSE-SU-2022:2104-1
SUSE-SU-2022:2111-1
SUSE-SU-2022:2116-1
SUSE-SU-2022:2177-1
SUSE-SU-2022:2393-1
SUSE-SU-2022:2629-1
SUSE-SU-2022_2077-1
SUSE-SU-2022_2078-1
SUSE-SU-2022_2079-1
SUSE-SU-2022_2082-1
SUSE-SU-2022_2103-1
SUSE-SU-2022_2111-1
SUSE-SU-2022_2393-1
USN-4367-1
USN-4367-2
USN-4369-1
USN-4414-1

Produtos afetados

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu