imPC@ndo IT

Tracker / CVE-2019-19807

CVE-2019-19807

High 7.8

In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.

Affected products and versions

canonical ubuntu_linux
linux linux_kernel · 4.14.152 → 4.14.154
linux linux_kernel · 4.19.82 → 4.19.84
linux linux_kernel · 4.9.199 → 4.9.201
linux linux_kernel · 5.2 → 5.3.11

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References