kernel: use-after-free in __blk_add_trace in kernel/trace/blktrace.c
Published Dec 12, 2019
7.5
HIGHCVSS 3.1
EPSS 4.15%
Description
In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).
Affected products
No data.
- 5.4.0
- 5.4.0
- 5.4.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1127.8.2.el7
Fixed · RHSA-2020:2082
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.21.2.el7a
Fixed · RHSA-2020:2104
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1127.8.2.rt56.1103.el7
Fixed · RHSA-2020:2085
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.88.1.el7
Fixed · RHSA-2020:2285
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.76.1.el7
Fixed · RHSA-2020:2277
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.76.1.el7
Fixed · RHSA-2020:2277
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.76.1.el7
Fixed · RHSA-2020:2277
Red Hat Enterprise Linux 7.4 Advanced Update Support
kernel-0:3.10.0-693.67.1.el7
Fixed · RHSA-2020:2214
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
kernel-0:3.10.0-693.67.1.el7
Fixed · RHSA-2020:2214
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
kernel-0:3.10.0-693.67.1.el7
Fixed · RHSA-2020:2214
Red Hat Enterprise Linux 7.6 Extended Update Support
kernel-0:3.10.0-957.54.1.el7
Fixed · RHSA-2020:2289
Red Hat Enterprise Linux 7.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2020:2291
Red Hat Enterprise Linux 7.7 Extended Update Support
kernel-0:3.10.0-1062.26.1.el7
Fixed · RHSA-2020:2522
Red Hat Enterprise Linux 7.7 Extended Update Support
kpatch-patch
Fixed · RHSA-2020:2519
Red Hat Enterprise Linux 8
kernel-0:4.18.0-193.el8
Fixed · RHSA-2020:1769
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-193.rt13.51.el8
Fixed · RHSA-2020:1567
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
kernel-0:4.18.0-80.18.1.el8_0
Fixed · RHSA-2020:1966
Red Hat Enterprise Linux 8.1 Extended Update Support
kernel-0:4.18.0-147.13.2.el8_1
Fixed · RHSA-2020:2199
Red Hat Enterprise Linux 8.1 Extended Update Support
kpatch-patch
Fixed · RHSA-2020:2203
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.67.1.rt56.665.el6rt
Fixed · RHSA-2020:2242
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
kernel-0:3.10.0-957.54.1.el7
Fixed · RHSA-2020:2289
Red Hat Enterprise Linux 5
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1127.8.2.el7 | Fixed | RHSA-2020:2082 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.21.2.el7a | Fixed | RHSA-2020:2104 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1127.8.2.rt56.1103.el7 | Fixed | RHSA-2020:2085 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.88.1.el7 | Fixed | RHSA-2020:2285 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.76.1.el7 | Fixed | RHSA-2020:2277 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.76.1.el7 | Fixed | RHSA-2020:2277 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.76.1.el7 | Fixed | RHSA-2020:2277 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | kernel-0:3.10.0-693.67.1.el7 | Fixed | RHSA-2020:2214 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | kernel-0:3.10.0-693.67.1.el7 | Fixed | RHSA-2020:2214 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | kernel-0:3.10.0-693.67.1.el7 | Fixed | RHSA-2020:2214 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kernel-0:3.10.0-957.54.1.el7 | Fixed | RHSA-2020:2289 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2020:2291 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | kernel-0:3.10.0-1062.26.1.el7 | Fixed | RHSA-2020:2522 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | kpatch-patch | Fixed | RHSA-2020:2519 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-193.el8 | Fixed | RHSA-2020:1769 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-193.rt13.51.el8 | Fixed | RHSA-2020:1567 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | kernel-0:4.18.0-80.18.1.el8_0 | Fixed | RHSA-2020:1966 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | kernel-0:4.18.0-147.13.2.el8_1 | Fixed | RHSA-2020:2199 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | kpatch-patch | Fixed | RHSA-2020:2203 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.67.1.rt56.665.el6rt | Fixed | RHSA-2020:2242 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | kernel-0:3.10.0-957.54.1.el7 | Fixed | RHSA-2020:2289 |
| Red Hat Enterprise Linux 5 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-19768 Vendor Advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=205711 x_refsource_MISCIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1786164 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-19768
- https://security.netapp.com/advisory/ntap-20200103-0001/ x_refsource_CONFIRM
- https://usn.ubuntu.com/4342-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4344-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4345-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4346-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-19768
- https://www.debian.org/security/2020/dsa-4698 vendor-advisoryx_refsource_DEBIAN
Change history (0)
No recorded changes yet.