ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19037 | third party advisory exploit |
https://security.netapp.com/advisory/ntap-20191205-0001/ | |
https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html | mailing list |