Cybersecurity Team Holiday Guide: 2019 Gag Gift Edition

Cybersecurity Team Holiday Guide: 2019 Gag Gift Edition
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2019-19318PUBLISHED: 2019-11-28

In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,

CVE-2019-19319PUBLISHED: 2019-11-27

In the Linux kernel 5.0.21, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call.

cybersecurity holiday guide edition