CVE-2019-19377: Use After Free
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfsqueuework in fs/btrfs/async-thread.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19377?
CVE-2019-19377 is classified with high severity due to the potential for a use-after-free vulnerability allowing for arbitrary code execution.
How do I fix CVE-2019-19377?
To fix CVE-2019-19377, upgrade your kernel to version 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, or 6.12.10-1.
What systems are affected by CVE-2019-19377?
CVE-2019-19377 affects Linux kernel versions between 2.6.12 and 5.4.33, as well as versions up to 5.6.5.
What type of vulnerability is CVE-2019-19377?
CVE-2019-19377 is a use-after-free vulnerability stemming from operations on a crafted btrfs filesystem image.
Can CVE-2019-19377 lead to system crashes?
Yes, exploitation of CVE-2019-19377 can potentially lead to system crashes or create instability in affected systems.