The Linux kernel before 5.1-rc5 allows page->refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipefs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11487.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.216"
}
]
},
{
"events": [
{
"introduced": "4.5"
},
{
"fixed": "4.9.181"
}
]
},
{
"events": [
{
"introduced": "4.10"
},
{
"fixed": "4.14.116"
}
]
},
{
"events": [
{
"introduced": "4.15"
},
{
"fixed": "4.19.39"
}
]
},
{
"events": [
{
"introduced": "4.20"
},
{
"fixed": "5.0.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.1-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.1-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.1-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.1-rc4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.04"
}
]
}
]