blob: 563850e3d0eb6a4760bd5ce0a2cb2145c29b6d99 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
|
Description: btrfs: crafted image triggers WARN() in __btrfs_free_extent
References:
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19039
Notes:
bwh> The reporter describes this as an information leak because a WARN()
bwh> causes register contents to be logged. This is mitigated on stretch
bwh> onward because we restrict access to the kernel log by default.
bwh> However this can still be a denial-of-service if panic_on_warn is
bwh> enabled.
Bugs:
upstream: needed
4.19-upstream-stable:
4.9-upstream-stable:
3.16-upstream-stable: ignored "EOL"
sid: needed
4.19-buster-security:
4.9-stretch-security:
3.16-jessie-security: ignored "EOL"
|