summaryrefslogtreecommitdiffstats
path: root/active/CVE-2019-19039
blob: 23b20f469f112e5c7c12e83730b01c5963cbe50d (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
Description: btrfs: crafted image triggers WARN() in __btrfs_free_extent
References:
 https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19039
Notes:
 bwh> The reporter describes this as an information leak because a WARN()
 bwh> causes register contents to be logged.  This is mitigated on stretch
 bwh> onward because we restrict access to the kernel log by default.
 bwh> However this can still be a denial-of-service if panic_on_warn is
 bwh> enabled.  Apparently fixed along with CVE-2019-19377.
Bugs:
upstream: released (5.7-rc1) [b3ff8f1d380e65dddd772542aa9bff6c86bf715a]
5.10-upstream-stable: N/A "Fixed before branch point"
4.19-upstream-stable: released (4.19.156) [1527c0e0229d2dd1c8ae1e73b1579bd8d5866b5b]
4.9-upstream-stable: needed
3.16-upstream-stable: ignored "EOL"
sid: released (5.6.7-1)
5.10-bullseye-security: N/A "Fixed before branching point"
4.19-buster-security: released (4.19.160-1)
4.9-stretch-security: needed
3.16-jessie-security: ignored "EOL"

© 2014-2024 Faster IT GmbH | imprint | privacy policy