PT-2019-6376 · Linux+2 · Linux Kernel+2
CVE-2019-19378
·
Publicado
2019-06-21
·
Atualizado
2026-08-30
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 5.0.21
Description
The issue is related to the
index rbio pages() function in the fs/btrfs/raid56.c module of the btrfs filesystem in the Linux operating system. It involves a slab-out-of-bounds write access when mounting a crafted btrfs filesystem image. This can potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information.Recommendations
For Linux kernel version 5.0.21, consider disabling the
index rbio pages() function as a temporary workaround until a patch is available. Restrict access to the fs/btrfs/raid56.c module to minimize the risk of exploitation. Avoid using crafted btrfs filesystem images until the issue is resolved.Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Linux Kernel