An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
2019-05-07T14:29:00.303
2024-11-21T04:02:16.550
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 3.16.72 | Yes |
Operating System | linux | linux_kernel | < 3.18.140 | Yes |
Operating System | linux | linux_kernel | < 4.4.180 | Yes |
Operating System | linux | linux_kernel | < 4.9.175 | Yes |
Operating System | linux | linux_kernel | < 4.14.118 | Yes |
Operating System | linux | linux_kernel | < 4.19.42 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Application | f5 | traffix_signaling_delivery_controller | 5.0.0 | Yes |
Application | f5 | traffix_signaling_delivery_controller | 5.1.0 | Yes |
Application | netapp | active_iq_unified_manager | ≥ 9.5 | Yes |
Application | netapp | snapprotect | - | Yes |
Application | netapp | solidfire_\&_hci_management_node | - | Yes |
Application | netapp | solidfire_\&_hci_storage_node | - | Yes |
Application | netapp | storage_replication_adapter_for_clustered_data_ontap | - | Yes |
Application | netapp | vasa_provider_for_clustered_data_ontap | ≥ 7.2 | Yes |
Application | netapp | virtual_storage_console | ≥ 7.2 | Yes |
Hardware | netapp | hci_compute_node | - | Yes |
Operating System | opensuse | leap | 15.0 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |