In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:35
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.html - | |
References | () https://bugzilla.kernel.org/show_bug.cgi?id=205711 - Issue Tracking, Vendor Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html - | |
References | () https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html - | |
References | () https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html - | |
References | () https://security.netapp.com/advisory/ntap-20200103-0001/ - | |
References | () https://usn.ubuntu.com/4342-1/ - | |
References | () https://usn.ubuntu.com/4344-1/ - | |
References | () https://usn.ubuntu.com/4345-1/ - | |
References | () https://usn.ubuntu.com/4346-1/ - | |
References | () https://www.debian.org/security/2020/dsa-4698 - |
Information
Published : 2019-12-12 20:15
Updated : 2024-11-21 04:35
NVD link : CVE-2019-19768
Mitre link : CVE-2019-19768
CVE.ORG link : CVE-2019-19768
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free