CVE-2019-19816: High severity Linux Linux kernel vulnerability
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in btrfsmapblock in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19816?
CVE-2019-19816 is classified as a high severity vulnerability due to its potential to lead to arbitrary memory corruption in the Linux kernel.
How do I fix CVE-2019-19816?
To fix CVE-2019-19816, you should update your Linux kernel to version 5.10.223-1 or later, as well as other affected package versions provided by your distribution.
Which versions of the Linux kernel are affected by CVE-2019-19816?
CVE-2019-19816 affects Linux kernel versions from 2.6.12 up to 5.2, specifically within certain ranges.
Can CVE-2019-19816 be exploited remotely?
Yes, CVE-2019-19816 can be exploited remotely through a crafted btrfs filesystem image.
What are the potential impacts of CVE-2019-19816?
Exploitation of CVE-2019-19816 can lead to system crashes, potential data corruption, and unauthorized access to sensitive data.