PT-2019-4484 · Linux+2 · Linux Kernel+2

Published

2019-06-21

·

Updated

2025-09-29

·

CVE-2019-19448

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.0.21 and 5.3.11
Description The issue is related to the use of memory after it has been freed in the try merge free space function of the Linux kernel, specifically in the fs/btrfs/free-space-cache.c file. This can be exploited by mounting a crafted btrfs filesystem image, performing certain operations, and then making a syncfs system call, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel version 5.0.21, update to a version that contains a fix for this issue. For Linux kernel version 5.3.11, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting the use of the btrfs filesystem until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2019-3180
ALT-PU-2019-3268
ALT-PU-2020-2659
ALT-PU-2020-2660
ALT-PU-2020-2695
ALT-PU-2020-2710
ALT-PU-2020-2726
ALT-PU-2020-2732
ALT-PU-2020-3057
ALT-PU-2021-1745
BDU:2020-00304
CVE-2019-19448
DLA-2385-1
DLA-2420-1
DLA-2420-2
ELSA-2020-5913
ELSA-2021-9459
MGASA-2020-0355
USN-4578-1

Affected Products

Alt Linux
Linux Kernel
Ubuntu