CVE-2019-19448
published 2019-12-08CVE-2019-19448: In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.14%
80.2th percentile
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.7.17-1 (bookworm) | linux 5.7.17-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.7.17-1 | 5.7.17-1 |
| linux | linux_kernel | >= 0 < 5.7.17-1 | 5.7.17-1 |
| linux | linux_kernel | >= 0 < 5.7.17-1 | 5.7.17-1 |
| linux | linux_kernel | >= 0 < 5.7.17-1 | 5.7.17-1 |
| linux | linux_kernel | >= 0 < 4.15.0-121.123 | 4.15.0-121.123 |
| linux | linux_kernel | >= 2.6.31 < 4.4.233 | 4.4.233 |
| linux | linux_kernel | >= 4.10 < 4.14.194 | 4.14.194 |
| linux | linux_kernel | >= 4.15 < 4.19.141 | 4.19.141 |
| linux | linux_kernel | >= 4.20 < 5.4.60 | 5.4.60 |
| linux | linux_kernel | >= 4.5.0 < 4.9.233 | 4.9.233 |
| linux | linux_kernel | >= 5.5.0 < 5.7.17 | 5.7.17 |
| linux | linux_kernel | >= 5.8 < 5.8.3 | 5.8.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-10-14·CVSS 5.5
CVE-2020-26088 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Hadar Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-16119)
Wen Xu discovered that the XFS file system in the Linux kernel did not
properly validate inode metadata in some situations. An attacker could use
this to construct a malicious XFS image that, when mounted, could cause a
denial of service (system crash). (CVE-2018-10322)
It was discovered that the btrfs file system in the Linux kernel contained
a use-after-free vulnerability when merging free space. An atta
Red Hat
kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c
vendor_redhat·2019-12-10·CVSS 7.8
CVE-2019-19448 [HIGH] CWE-416 kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c
kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
A flaw was found in the Linux kernel's implementation of BTRFS free space management, where the kernel does not correctly manage the lifetime of internal data structures used. An attacker could use this flaw to corrupt memory or escalate privileges.
Mitigation: I
Debian
CVE-2019-19448: linux - In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image...
vendor_debian·2019·CVSS 7.8
CVE-2019-19448 [HIGH] CVE-2019-19448: linux - In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image...
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
Scope: local
bookworm: resolved (fixed in 5.7.17-1)
bullseye: resolved (fixed in 5.7.17-1)
forky: resolved (fixed in 5.7.17-1)
sid: resolved (fixed in 5.7.17-1)
trixie: resolved (fixed in 5.7.17-1)
GHSA
GHSA-55vw-8vf8-x898: In the Linux kernel 5
ghsa_unreviewed·2022-05-24
CVE-2019-19448 [MEDIUM] CWE-416 GHSA-55vw-8vf8-x898: In the Linux kernel 5
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2020-10-14·CVSS 5.5
CVE-2020-16119 [MEDIUM] linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
Hadar Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-16119)
Wen Xu discovered that the XFS file system in the Linux kernel did not
properly validate inode metadata in some situations. An attacker could use
this to construct a malicious XFS image that, when mounted, could cause a
denial of service (system crash). (CVE-2018-10322)
It was discovered that the btrfs file s
Kernel
btrfs: only search for left_info if there is no right_info in try_merge_free_space
kernel_security·2020-07-27·CVSS 7.8
CVE-2019-19448 [HIGH] btrfs: only search for left_info if there is no right_info in try_merge_free_space
btrfs: only search for left_info if there is no right_info in try_merge_free_space
In try_to_merge_free_space we attempt to find entries to the left and
right of the entry we are adding to see if they can be merged. We
search for an entry past our current info (saved into right_info), and
then if right_info exists and it has a rb_prev() we save the rb_prev()
into left_info.
However there's a slight problem in the case that we have a right_info,
but no entry previous to that entry. At that point we will search for
an entry just before the info we're attempting to insert. This will
simply find right_info again, and assign it to left_info, making them
both the same pointer.
Now if right_info _can_ be merged with the range we're inserting, we'll
add it to the info and free right_info. Howev
OSV
CVE-2019-19448: In the Linux kernel 5
osv·2019-12-08·CVSS 7.8
CVE-2019-19448 [HIGH] CVE-2019-19448: In the Linux kernel 5
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19448 kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free
bugzilla·2019-12-10·CVSS 7.8
CVE-2019-19448 [HIGH] CVE-2019-19448 kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free
CVE-2019-19448 kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c
A flaw was found in the Linux kernels BTRFS implementation where a local privileged attacker can mount a crafted BRTFS disk or image, modify files from the mount point then sync() the disk image. During the syncfs procedure, the kernel will attempt to consolidate free space and will cause a use-after-free while rebalancing an in-memory red-black tree.
This could lead to memory corruption, kernel panic and possibly privilege escalation.
External Reference:
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19448
Discussion:
Created kernel tracking bugs for this issue:
Bugzilla
CVE-2019-19448 kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free
bugzilla·2019-12-10·CVSS 7.8
CVE-2019-19448 [HIGH] CVE-2019-19448 kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free
CVE-2019-19448 kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
arXiv
MVD: Memory-Related Vulnerability Detection Based on Flow-Sensitive Graph Neural Networks
arxiv_fulltext·2022-03-05
MVD: Memory-Related Vulnerability Detection Based on Flow-Sensitive Graph Neural Networks
C[1]> p#1
MVD: Memory-Related Vulnerability Detection Based on Flow-Sensitive Graph Neural Networks
*Xiaobing Sun and Lili Bo are the corresponding authors.
Sicong Cao
Yangzhou University
Yangzhou
China
[email protected]
Xiaobing Sun
[1]
Yangzhou University
Yangzhou
China
[email protected]
Lili Bo
[1]
Yangzhou University
Yangzhou
China
[email protected]
Rongxin Wu
Xiamen University
Xiamen
China
[email protected]
Bin Li
Yangzhou University
Yangzhou
China
[email protected]
Chuanqi Tao
Nanjing University of Aeronautics and Astronautics
Nanjing
China
[email protected]
## Abstract
Memory-related vulnerabilities constitute severe threats to the security of modern software.
Despite the success of deep learning-based approaches to generic vulnerability detection,
they are
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19448https://lists.debian.org/debian-lts-announce/2020/09/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2020/10/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2020/10/msg00034.htmlhttps://security.netapp.com/advisory/ntap-20200103-0001/https://usn.ubuntu.com/4578-1/https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19448https://lists.debian.org/debian-lts-announce/2020/09/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2020/10/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2020/10/msg00034.htmlhttps://security.netapp.com/advisory/ntap-20200103-0001/https://usn.ubuntu.com/4578-1/
2019-12-08
Published