CVE-2019-19447

In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:h610s:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:34

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html - Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html - Third Party Advisory
References () https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19447 - Exploit, Third Party Advisory () https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19447 - Exploit, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html - Third Party Advisory () https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html - Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html - Third Party Advisory () https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html - Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html - Third Party Advisory () https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html - Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20200103-0001/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20200103-0001/ - Third Party Advisory

03 Oct 2023, 15:38

Type Values Removed Values Added
First Time Netapp hci Baseboard Management Controller
Netapp
Netapp cloud Backup
Netapp solidfire Baseboard Management Controller
Netapp steelstore Cloud Integrated Storage
Netapp data Availability Services
Netapp active Iq Unified Manager
References (MLIST) https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html - (MLIST) https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html - Third Party Advisory
References (CONFIRM) https://security.netapp.com/advisory/ntap-20200103-0001/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20200103-0001/ - Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html - (MLIST) https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html - Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html - (MLIST) https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html - Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html - Third Party Advisory
CPE cpe:2.3:o:linux:linux_kernel:5.0.21:*:*:*:*:*:*:* cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:h610s:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*

Information

Published : 2019-12-08 01:15

Updated : 2024-11-21 04:34


NVD link : CVE-2019-19447

Mitre link : CVE-2019-19447

CVE.ORG link : CVE-2019-19447


JSON object : View

Products Affected

netapp

  • cloud_backup
  • solidfire_baseboard_management_controller
  • steelstore_cloud_integrated_storage
  • data_availability_services
  • hci_baseboard_management_controller
  • active_iq_unified_manager

linux

  • linux_kernel
CWE
CWE-416

Use After Free