CVE-2019-19770

CVSS v3.1 8.2 (High)
82% Progress
CVSS v2.0 6.4 (Medium)
64% Progress
EPSS 0.23 % (61th)
0.23% Progress
Affected Products 1
Advisories 17
NVD Status Modified

In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file). NOTE: Linux kernel developers dispute this issue as not being an issue with debugfs, instead this is an issue with misuse of debugfs within blktrace

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
NVD Status
Modified
CNA
MITRE
Published Date
2019-12-12 20:15:17
(4 years ago)
Updated Date
2024-08-05 03:15:36
(6 weeks ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 4.19.83 and prior versions cpe:2.3:o:linux:linux_kernel <= 4.19.83
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...