CVE-2019-19377

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*

History

03 Oct 2023, 15:39

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:5.0.21:*:*:*:*:*:*:* cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
First Time Netapp steelstore Cloud Integrated Storage
Netapp active Iq Unified Manager
Netapp cloud Backup
Netapp
Netapp solidfire Baseboard Management Controller
References (CONFIRM) https://security.netapp.com/advisory/ntap-20200103-0001/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20200103-0001/ - Third Party Advisory, VDB Entry
References (UBUNTU) https://usn.ubuntu.com/4369-1/ - (UBUNTU) https://usn.ubuntu.com/4369-1/ - Third Party Advisory
References (UBUNTU) https://usn.ubuntu.com/4414-1/ - (UBUNTU) https://usn.ubuntu.com/4414-1/ - Third Party Advisory
References (UBUNTU) https://usn.ubuntu.com/4367-1/ - (UBUNTU) https://usn.ubuntu.com/4367-1/ - Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html - (MLIST) https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html - Mailing List, Third Party Advisory

Information

Published : 2019-11-29 16:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-19377

Mitre link : CVE-2019-19377

CVE.ORG link : CVE-2019-19377


JSON object : View

Products Affected

netapp

  • active_iq_unified_manager
  • cloud_backup
  • solidfire_baseboard_management_controller
  • steelstore_cloud_integrated_storage

linux

  • linux_kernel
CWE
CWE-416

Use After Free