In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.
2019-12-08T01:15:10.383
2024-11-21T04:34:45.017
Modified
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 3.16.82 | Yes |
Operating System | linux | linux_kernel | < 4.4.208 | Yes |
Operating System | linux | linux_kernel | < 4.9.208 | Yes |
Operating System | linux | linux_kernel | < 4.14.159 | Yes |
Operating System | linux | linux_kernel | < 4.19.90 | Yes |
Operating System | linux | linux_kernel | < 5.3.17 | Yes |
Operating System | linux | linux_kernel | < 5.4.4 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | data_availability_services | - | Yes |
Application | netapp | hci_baseboard_management_controller | h610s | Yes |
Application | netapp | steelstore_cloud_integrated_storage | - | Yes |
Hardware | netapp | solidfire_baseboard_management_controller | - | Yes |