VDB

CVE-2019-10125

CVE-2019-10125 REJECTED

An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfs_poll(), and this will cause a use-after-free.

EPSS 3.43% · 87.7th percentile

Risk Scores

EPSS Score
3.43%
87.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-aws0
Ubuntu:18.04:LTSlinux-hwe0
Ubuntu:18.04:LTSlinux-gcp-edge0
Ubuntu:16.04:LTSlinux0
Ubuntu:18.04:LTSlinux-oracle0
Ubuntu:18.04:LTSlinux0
Ubuntu:18.04:LTSlinux-azure0
Ubuntu:14.04:LTSlinux-azure0
Ubuntu:16.04:LTSlinux-hwe0
Ubuntu:18.04:LTSlinux-kvm0
Ubuntu:18.04:LTSlinux-oem0
Ubuntu:16.04:LTSlinux-raspi20
Ubuntu:18.04:LTSlinux-raspi20
Ubuntu:16.04:LTSlinux-azure0
Ubuntu:16.04:LTSlinux-gcp0
Ubuntu:16.04:LTSlinux-oracle0
Ubuntu:18.04:LTSlinux-gcp0
Ubuntu:16.04:LTSlinux-aws-hwe0
Ubuntu:18.04:LTSlinux-snapdragon0
Ubuntu:14.04:LTSlinux-aws0

…and 5 more

Timeline

  • Mar 27, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›