CVE-2019-19377

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:34

Type Values Removed Values Added
References () https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19377 - Exploit, Third Party Advisory () https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19377 - Exploit, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html - Mailing List, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20200103-0001/ - Third Party Advisory, VDB Entry () https://security.netapp.com/advisory/ntap-20200103-0001/ - Third Party Advisory, VDB Entry
References () https://usn.ubuntu.com/4367-1/ - Third Party Advisory () https://usn.ubuntu.com/4367-1/ - Third Party Advisory
References () https://usn.ubuntu.com/4369-1/ - Third Party Advisory () https://usn.ubuntu.com/4369-1/ - Third Party Advisory
References () https://usn.ubuntu.com/4414-1/ - Third Party Advisory () https://usn.ubuntu.com/4414-1/ - Third Party Advisory

03 Oct 2023, 15:39

Type Values Removed Values Added
First Time Netapp
Netapp cloud Backup
Netapp solidfire Baseboard Management Controller
Netapp steelstore Cloud Integrated Storage
Netapp active Iq Unified Manager
CPE cpe:2.3:o:linux:linux_kernel:5.0.21:*:*:*:*:*:*:* cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
References (UBUNTU) https://usn.ubuntu.com/4414-1/ - (UBUNTU) https://usn.ubuntu.com/4414-1/ - Third Party Advisory
References (CONFIRM) https://security.netapp.com/advisory/ntap-20200103-0001/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20200103-0001/ - Third Party Advisory, VDB Entry
References (UBUNTU) https://usn.ubuntu.com/4369-1/ - (UBUNTU) https://usn.ubuntu.com/4369-1/ - Third Party Advisory
References (UBUNTU) https://usn.ubuntu.com/4367-1/ - (UBUNTU) https://usn.ubuntu.com/4367-1/ - Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html - (MLIST) https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html - Mailing List, Third Party Advisory

Information

Published : 2019-11-29 16:15

Updated : 2024-11-21 04:34


NVD link : CVE-2019-19377

Mitre link : CVE-2019-19377

CVE.ORG link : CVE-2019-19377


JSON object : View

Products Affected

netapp

  • cloud_backup
  • solidfire_baseboard_management_controller
  • steelstore_cloud_integrated_storage
  • active_iq_unified_manager

linux

  • linux_kernel
CWE
CWE-416

Use After Free