CVE-2019-19318
moderate-risk
Published 2019-11-28
In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,
Do I need to act?
-
0.35% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.4/10
Medium
LOCAL
/ LOW complexity
Affected Products (17)
Aff A700S Firmware
Fas8300 Firmware
Fas8700 Firmware
References (10)
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200103-0001/
Third Party Advisory
https://usn.ubuntu.com/4414-1/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200103-0001/
Third Party Advisory
https://usn.ubuntu.com/4414-1/
35
/ 100
moderate-risk
Severity
15/34 · Moderate
Exploitability
1/34 · Minimal
Exposure
19/34 · Moderate