Unknown
CVE-2019-19448
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2019-19448
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- canonical,
- debian,
- linux,
- netapp
Products
- a700s firmware -,
- active iq unified manager -,
- aff 8300 firmware -,
- aff 8700 firmware -,
- aff a400 firmware -,
- cloud backup -,
- data availability services -,
- debian linux 9.0,
- fas 8300 firmware -,
- fas 8700 firmware -,
- fas a400 firmware -,
- h610s firmware -,
- hci management node -,
- linux kernel,
- solidfire -,
- solidfire baseboard management controller firmware -,
- steelstore cloud integrated storage -,
- ubuntu linux 14.04,
- ubuntu linux 16.04,
- ubuntu linux 18.04
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: