imPC@ndo IT

Tracker / CVE-2019-19318

CVE-2019-19318

Medium 4.4

In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel
netapp active_iq_unified_manager · 9.5 → …
netapp aff_a400_firmware
netapp aff_a700s_firmware
netapp data_availability_services
netapp fas8300_firmware
netapp fas8700_firmware
netapp h610s_firmware
netapp hci_management_node
netapp solidfire
netapp steelstore_cloud_integrated_storage
opensuse leap

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References