imPC@ndo IT

Tracker / CVE-2019-19447

CVE-2019-19447

High 7.8

In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.

Affected products and versions

linux linux_kernel · 2.6.12 → 3.16.82
linux linux_kernel · 3.17 → 4.4.208
linux linux_kernel · 4.10 → 4.14.159
linux linux_kernel · 4.15 → 4.19.90
linux linux_kernel · 4.20 → 5.3.17
linux linux_kernel · 4.5.0 → 4.9.208
linux linux_kernel · 5.4 → 5.4.4
netapp active_iq_unified_manager
netapp cloud_backup
netapp data_availability_services
netapp hci_baseboard_management_controller
netapp solidfire_baseboard_management_controller
netapp steelstore_cloud_integrated_storage

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References