CVE-2019-19447

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.

References

http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html

https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19447

https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html

https://security.netapp.com/advisory/ntap-20200103-0001/

Details

Source: MITRE

Published: 2019-12-08

Updated: 2020-06-10

Type: CWE-416

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:5.0.21:*:*:*:*:*:*:*

Tenable Plugins

View all (37 total)

IDNameProductFamilySeverity
145806CentOS 8 : kernel (CESA-2020:4431)NessusCentOS Local Security Checks
medium
144837OracleVM 3.4 : Unbreakable / etc (OVMSA-2021-0001)NessusOracleVM Local Security Checks
high
144802Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2021-9002)NessusOracle Linux Local Security Checks
high
144554RHEL 7 : kernel (RHSA-2020:5656)NessusRed Hat Local Security Checks
high
144280RHEL 7 : kernel (RHSA-2020:5430)NessusRed Hat Local Security Checks
medium
143241RHEL 7 : kernel (RHSA-2020:5206)NessusRed Hat Local Security Checks
high
142430RHEL 8 : kernel (RHSA-2020:4431)NessusRed Hat Local Security Checks
medium
142382RHEL 8 : kernel-rt (RHSA-2020:4609)NessusRed Hat Local Security Checks
medium
141727Scientific Linux Security Update : kernel on SL7.x x86_64 (20201001)NessusScientific Linux Local Security Checks
high
141619CentOS 7 : kernel (CESA-2020:4060)NessusCentOS Local Security Checks
high
141057RHEL 7 : kernel (RHSA-2020:4060)NessusRed Hat Local Security Checks
high
141026RHEL 7 : kernel-rt (RHSA-2020:4062)NessusRed Hat Local Security Checks
high
140917EulerOS 2.0 SP3 : kernel (EulerOS-SA-2020-2150)NessusHuawei Local Security Checks
medium
140382SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2498-1)NessusSuSE Local Security Checks
critical
140381SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2497-1)NessusSuSE Local Security Checks
critical
140380SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2492-1)NessusSuSE Local Security Checks
critical
140379SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2491-1)NessusSuSE Local Security Checks
critical
139476Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5804)NessusOracle Linux Local Security Checks
high
138272SUSE SLES15 Security Update : kernel (SUSE-SU-2020:1663-1)NessusSuSE Local Security Checks
critical
137283Debian DLA-2241-2 : linux security updateNessusDebian Local Security Checks
medium
136782SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1275-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusSuSE Local Security Checks
critical
136661SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1255-1)NessusSuSE Local Security Checks
critical
136496RHEL 7 : kernel-alt (RHSA-2020:2104)NessusRed Hat Local Security Checks
high
136239EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1536)NessusHuawei Local Security Checks
critical
135614EulerOS Virtualization 3.0.2.2 : kernel (EulerOS-SA-2020-1452)NessusHuawei Local Security Checks
high
135155EulerOS Virtualization for ARM 64 3.0.6.0 : kernel (EulerOS-SA-2020-1368)NessusHuawei Local Security Checks
high
134784EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-1292)NessusHuawei Local Security Checks
high
134559openSUSE Security Update : the Linux Kernel (openSUSE-2020-336)NessusSuSE Local Security Checks
critical
134363SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:0613-1)NessusSuSE Local Security Checks
critical
134293SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0584-1)NessusSuSE Local Security Checks
critical
134292SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0580-1)NessusSuSE Local Security Checks
critical
134289SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:0560-1)NessusSuSE Local Security Checks
critical
134288SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0559-1)NessusSuSE Local Security Checks
critical
134240Debian DLA-2114-1 : linux-4.9 security updateNessusDebian Local Security Checks
critical
133913EulerOS 2.0 SP5 : kernel (EulerOS-SA-2020-1112)NessusHuawei Local Security Checks
critical
133295Photon OS 3.0: Linux PHSA-2020-3.0-0052NessusPhotonOS Local Security Checks
high
132925SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0093-1)NessusSuSE Local Security Checks
critical