CVE-2019-19447

Source
https://cve.org/CVERecord?id=CVE-2019-19447
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19447.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-19447
Downstream
Related
Published
2019-12-08T01:15:10.383Z
Modified
2026-02-21T01:15:05.916246Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4putsuper in fs/ext4/super.c, related to dumporphanlist in fs/ext4/super.c.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
e77ff35fa79353a8bd85a33b83609bd3add65e4b
Introduced
219d54332a09e8d8741c1e1982f5eae56099de85
Fixed
dc71226e59c276e531e6a512cdcf821b44ceb323
Introduced
26791a8bcf0e6d33f43aef7682bdb555236d56de
Fixed
4f0eaca39dd14d3492f6bbdd02b9657a180e6c03
Introduced
850bc05248749f47b0c0a64af52cfe213bdec385
Fixed
38bb70c252a9d238e4713d5ef407dc76e193330f
Introduced
8fe28cb58bcb235034b64cbbb7550a8a43fd88be
Fixed
e736b667a96215f6ef2d805e4b010ae5ee586310
Introduced
b6b09084ce3842fce3d4ba4d663d6019116bbb09
Fixed
b41d70cff22b17b7e3038349a918fe24fa22fca1
Introduced
f5b7ec87f701326704545ebfc8fe4a2aa42086aa
Fixed
bf530d77a1a081b43e8e347c3da090fd1382a7d8

Affected versions

v4.*
v4.20
v5.*
v5.0
v5.0-rc1
v5.0-rc2
v5.0-rc3
v5.0-rc4
v5.0-rc5
v5.0-rc6
v5.0-rc7
v5.0-rc8
v5.1
v5.1-rc1
v5.1-rc2
v5.1-rc3
v5.1-rc4
v5.1-rc5
v5.1-rc6
v5.1-rc7
v5.2
v5.2-rc1
v5.2-rc2
v5.2-rc3
v5.2-rc4
v5.2-rc5
v5.2-rc6
v5.2-rc7
v5.3
v5.3-rc1
v5.3-rc2
v5.3-rc3
v5.3-rc4
v5.3-rc5
v5.3-rc6
v5.3-rc7
v5.3-rc8
v5.3.1
v5.3.10
v5.3.11
v5.3.12
v5.3.13
v5.3.14
v5.3.15
v5.3.16
v5.3.17
v5.3.18
v5.3.2
v5.3.3
v5.3.4
v5.3.5
v5.3.6
v5.3.7
v5.3.8
v5.3.9
v5.4
v5.4.1
v5.4.2
v5.4.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19447.json"