UBUNTU-CVE-2019-19813
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-19813
UBUNTU-CVE-2019-19813
Summary:
Details: In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/delayed-inode.c.
References: https://ubuntu.com/security/CVE-2019-19813, https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19813, https://ubuntu.com/security/notices/USN-4414-1, https://ubuntu.com/security/notices/USN-4709-1, https://ubuntu.com/security/notices/USN-4708-1, https://www.cve.org/CVERecord?id=CVE-2019-19813
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
