CVE-2019-19813

CVSS v3.1 5.5 (Medium)
55% Progress
CVSS v2.0 7.1 (High)
71% Progress
EPSS 0.07 % (32th)
0.07% Progress
Affected Products 18
Advisories 6

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/delayed-inode.c.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2019-12-17 06:15:12
(4 years ago)
Updated Date
2021-03-12 16:11:33
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Linux Kernel 5.0.21 cpe:2.3:o:linux:linux_kernel:5.0.21

Configuration #2

AND
    CPE23 From Up To
OR  
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm
OR  
  Running on/with
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts
OR  
  Running on/with
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts

Configuration #3

AND
    CPE23 From Up To
OR  
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0

Configuration #4

AND
    CPE23 From Up To
OR  
  Netapp Active Iq Unified Manager for Vmware Vsphere from 9.5 version cpe:2.3:a:netapp:active_iq_unified_manager::*:*:*:*:vmware_vsphere >= 9.5
OR  
  Running on/with
  Netapp Data Availability Services cpe:2.3:a:netapp:data_availability_services:-
OR  
  Running on/with
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
OR  
  Running on/with
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-
OR  
  Running on/with
  Netapp Steelstore Cloud Integrated Storage cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-

Configuration #5

AND
    CPE23 From Up To
OR  
  Netapp Aff A700s Firmware cpe:2.3:o:netapp:aff_a700s_firmware:-
OR  
  Running on/with
  Netapp Aff A700s cpe:2.3:h:netapp:aff_a700s:-

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp Fas8300 Firmware cpe:2.3:o:netapp:fas8300_firmware:-
OR  
  Running on/with
  Netapp Fas8300 cpe:2.3:h:netapp:fas8300:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp Fas8700 Firmware cpe:2.3:o:netapp:fas8700_firmware:-
OR  
  Running on/with
  Netapp Fas8700 cpe:2.3:h:netapp:fas8700:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp Aff A400 Firmware cpe:2.3:o:netapp:aff_a400_firmware:-
OR  
  Running on/with
  Netapp Aff A400 cpe:2.3:h:netapp:aff_a400:-

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H610s Firmware cpe:2.3:o:netapp:h610s_firmware:-
OR  
  Running on/with
  Netapp H610s cpe:2.3:h:netapp:h610s:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...