CVE-2019-10125: Use After Free
An issue was discovered in aiopoll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aiopollwake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfspoll(), and this will cause a use-after-free.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-10125?
CVE-2019-10125 is a vulnerability discovered in aio_poll() in fs/aio.c in the Linux kernel through version 5.0.4, which can lead to a use-after-free when certain conditions are met.
How severe is CVE-2019-10125?
CVE-2019-10125 has a severity level of 9.8, which is considered critical.
Which software is affected by CVE-2019-10125?
The Linux kernel versions 4.19.38 to 5.0.4 and Netapp products such as Active IQ Unified Manager, HCI Management Node, Snapprotect, Solidfire, and CN1610 Firmware are affected by CVE-2019-10125.
How can I fix CVE-2019-10125?
To fix CVE-2019-10125, update your Linux kernel to version 5.0.5 or later, and apply any necessary patches provided by your vendor for Netapp products.
Where can I find more information about CVE-2019-10125?
You can find more information about CVE-2019-10125 at the following references: http://www.securityfocus.com/bid/107655, https://patchwork.kernel.org/patch/10828359/, and https://security.netapp.com/advisory/ntap-20190411-0003/