PT-2019-4484 · Linux+2 · Linux Kernel+2
Published
2019-06-21
·
Updated
2025-09-29
·
CVE-2019-19448
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.0.21 and 5.3.11
Description
The issue is related to the use of memory after it has been freed in the try merge free space function of the Linux kernel, specifically in the fs/btrfs/free-space-cache.c file. This can be exploited by mounting a crafted btrfs filesystem image, performing certain operations, and then making a syncfs system call, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
For Linux kernel version 5.0.21, update to a version that contains a fix for this issue.
For Linux kernel version 5.3.11, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting the use of the btrfs filesystem until a patch is available.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Ubuntu