PT-2019-6223 · Linux+4 · Linux Kernel+4

Published

2019-06-21

·

Updated

2025-09-29

·

CVE-2019-19377

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 5.0.21
Description The issue is related to a use-after-free vulnerability in the btrfs queue work function, located in the fs/btrfs/async-thread.c file. This vulnerability can be exploited by mounting a crafted btrfs filesystem image, performing certain operations, and then unmounting it. The exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel version 5.0.21, consider applying a patch or updating to a newer version that addresses this issue. As a temporary workaround, restrict access to the btrfs queue work function in the fs/btrfs/async-thread.c file to minimize the risk of exploitation. Avoid mounting crafted btrfs filesystem images and performing operations that may trigger the use-after-free vulnerability until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2020-1849
ALT-PU-2020-1850
ALT-PU-2020-1851
ALT-PU-2020-1905
ALT-PU-2020-1945
ALT-PU-2020-2164
ALT-PU-2020-3057
ALT-PU-2021-1745
BDU:2022-05179
CVE-2019-19377
DLA-2483-1
ELSA-2020-5714
ELSA-2020-5913
ELSA-2022-10065
MGASA-2020-0183
MGASA-2020-0184
OPENSUSE-SU-2022:2177-1
OPENSUSE-SU-2022_2078-1
OPENSUSE-SU-2022_2079-1
OPENSUSE-SU-2022_2111-1
SUSE-SU-2022:2077-1
SUSE-SU-2022:2078-1
SUSE-SU-2022:2079-1
SUSE-SU-2022:2080-1
SUSE-SU-2022:2082-1
SUSE-SU-2022:2103-1
SUSE-SU-2022:2104-1
SUSE-SU-2022:2111-1
SUSE-SU-2022:2116-1
SUSE-SU-2022:2177-1
SUSE-SU-2022:2393-1
SUSE-SU-2022:2629-1
SUSE-SU-2022_2077-1
SUSE-SU-2022_2078-1
SUSE-SU-2022_2079-1
SUSE-SU-2022_2082-1
SUSE-SU-2022_2103-1
SUSE-SU-2022_2111-1
SUSE-SU-2022_2393-1
USN-4367-1
USN-4367-2
USN-4369-1
USN-4414-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu