An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfs_poll(), and this will cause a use-after-free.
2019-03-27T06:29:00.327
2024-11-21T04:18:27.907
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 4.19.38 | Yes |
Operating System | linux | linux_kernel | < 5.0.5 | Yes |
Operating System | linux | linux_kernel | 5.1 | Yes |
Application | netapp | active_iq_unified_manager | ≥ 9.5 | Yes |
Application | netapp | hci_management_node | - | Yes |
Application | netapp | snapprotect | - | Yes |
Application | netapp | solidfire | - | Yes |
Operating System | netapp | cn1610_firmware | - | Yes |
Hardware | netapp | cn1610 | - | No |