UBUNTU-CVE-2019-19768
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-19768
UBUNTU-CVE-2019-19768
Summary:
Details: In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).
References: https://ubuntu.com/security/CVE-2019-19768, https://bugzilla.kernel.org/show_bug.cgi?id=205711, https://lore.kernel.org/linux-block/[email protected]/, https://ubuntu.com/security/notices/USN-4342-1, https://ubuntu.com/security/notices/USN-4344-1, https://ubuntu.com/security/notices/USN-4345-1, https://ubuntu.com/security/notices/USN-4346-1, https://www.cve.org/CVERecord?id=CVE-2019-19768
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
