#VU34963 Out-of-bounds write in Linux kernel - CVE-2019-19814
Published: December 17, 2019 / Updated: August 8, 2020
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.