Tracker / CVE-2019-19807
CVE-2019-19807
High 7.8
In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| linux | linux_kernel · 4.14.152 → 4.14.154 |
| linux | linux_kernel · 4.19.82 → 4.19.84 |
| linux | linux_kernel · 4.9.199 → 4.9.201 |
| linux | linux_kernel · 5.2 → 5.3.11 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.