PT-2019-4424 · Linux+2 · Linux Kernel+2

Published

2019-02-25

·

Updated

2025-09-29

·

CVE-2019-18885

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.1
Description The issue is related to a NULL pointer dereference in the fs/btrfs/volumes.c file of the Linux kernel. This occurs due to mishandling of fs devices->devices within the find device function, which can be exploited by a crafted btrfs image. The exploitation of this issue may allow an attacker to cause a denial of service.
Recommendations For Linux kernel versions prior to 5.1, update to version 5.1 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific issue.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2019-1893
ALT-PU-2019-1896
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-00167
CVE-2019-18885
DLA-2323-1
ELSA-2020-5844
ELSA-2020-5845
ELSA-2020-5866
ELSA-2020-5885
USN-4254-1
USN-4254-2
USN-4258-1
USN-4287-1
USN-4287-2

Affected Products

Alt Linux
Linux Kernel
Ubuntu