The Linux kernel 5.0.21 contains a use after free vulnerability CVE-2019-19377. The vulnerability documented on 29.11.2019 with a CVE number is currently awaiting analysis.
Advertising
The following tweet mentions to the vulnerability CVE-2019-19377 in the Linux kernel 5.0.21.
CVE-2019-19377 | In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, a | | #Exploit #Vulnerability #InfoSec #Hackers
— ZeroSecVulns (@ZeroSecVulns) December 3, 2019
The problem: The Linux kernel 5.0.21 has a use-after-free vulnerability which can be exploited by operations like mounting a prepared btrfs file system image, performing some operations and unmounting. The error is in btrfs_queue_work in fs/btrfs/async-thread.c.
Advertising