In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,
CPE | Name | Operator | Version |
---|---|---|---|
ubuntu_linux | eq | 16.04 | |
ubuntu_linux | eq | 18.04 | |
ubuntu_linux | eq | 14.04 | |
debian_linux | eq | 9.0 | |
linux_kernel | eq | 5.0.21 | |
linux_kernel | eq | 5.3.11 | |
active_iq_unified_manager | ge | 9.5 | |
leap | eq | 15.1 |