CVE-2019-3885: Use After Free
Published Apr 1, 2019
·Updated
A use-after-free defect was discovered in pacemaker that can possibly lead to unsolicited information disclosure in the log outputs.
Other sources
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
— Launchpad
Affected Software
8 affected componentsFixes available
redhat/pacemaker<2.0.2
2.0.2
ClusterLabs Pacemaker<=2.0.1
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Canonical Ubuntu Linux=19.04
Fedoraproject Fedora=30
debian/pacemaker
2.0.5-22.1.5-1+deb12u13.0.0-23.0.1-1.1
Remediation
Patch Available
Patch Available
Event History
Apr 18, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Feb 20, 2026
Data Sourced
via Ubuntu·05:44 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·05:44 PM
Description
Data Sourced
via Debian·05:44 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-3885?
CVE-2019-3885 is a use-after-free vulnerability found in pacemaker up to and including version 2.0.1.
2
What is the severity of CVE-2019-3885?
The severity of CVE-2019-3885 is high with a CVSS score of 7.5.
3
How does CVE-2019-3885 impact pacemaker?
CVE-2019-3885 could result in certain sensitive information being leaked via the system logs in pacemaker.
4
Which software versions are affected by CVE-2019-3885?
Pacemaker versions up to and including 2.0.1 are affected by CVE-2019-3885.
5
How can I fix CVE-2019-3885 in pacemaker?
To fix CVE-2019-3885, upgrade pacemaker to version 2.0.2 or later.