In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| linux | linux_kernel | 2.6.31 - 4.4.233 | - |
| linux | linux_kernel | 4.5.0 - 4.9.233 | - |
| linux | linux_kernel | 4.10 - 4.14.194 |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
26
Affected Products
12
References
linux / linux_kernel
| - |
| linux | linux_kernel | 4.15 - 4.19.141 | - |
| linux | linux_kernel | 4.20 - 5.4.60 | - |
| linux | linux_kernel | 5.5.0 - 5.7.17 | - |
| linux | linux_kernel | 5.8 - 5.8.3 | - |
| debian | debian_linux | - | - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| netapp | active_iq_unified_manager | - | - |
| netapp | cloud_backup | - | - |
| netapp | data_availability_services | - | - |
| netapp | hci_management_node | - | - |
| netapp | solidfire | - | - |
| netapp | steelstore_cloud_integrated_storage | - | - |
| netapp | a700s_firmware | - | - |
| netapp | fas_8300_firmware | - | - |
| netapp | fas_8700_firmware | - | - |
| netapp | fas_a400_firmware | - | - |
| netapp | aff_8300_firmware | - | - |
| netapp | aff_8700_firmware | - | - |
| netapp | aff_a400_firmware | - | - |
| netapp | h610s_firmware | - | - |
| netapp | solidfire_baseboard_management_controller_firmware | - | - |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability
Impact