PT-2019-6376 · Linux+2 · Linux Kernel+2
Published
2019-06-21
·
Updated
2026-05-26
·
CVE-2019-19378
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 5.0.21
Description
The issue is related to the
index rbio pages() function in the fs/btrfs/raid56.c module of the btrfs filesystem in the Linux operating system. It involves a slab-out-of-bounds write access when mounting a crafted btrfs filesystem image. This can potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information.Recommendations
For Linux kernel version 5.0.21, consider disabling the
index rbio pages() function as a temporary workaround until a patch is available. Restrict access to the fs/btrfs/raid56.c module to minimize the risk of exploitation. Avoid using crafted btrfs filesystem images until the issue is resolved.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linux Kernel