Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-11599

34
FAUCET Score

CVE-2019-11599 is a race condition vulnerability in the Linux kernel's coredump implementation, affecting versions prior to 5.0.10. This flaw allows local users to trigger a race condition during coredump generation, potentially leading to sensitive information disclosure, denial of service, or other unspecified impacts. With a CVSS score of 7.0 (HIGH), the attack requires low privileges and high attack complexity, but can result in high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, a proof-of-concept exploit is available on ExploitDB, and the vulnerability has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.16.12, < 3.16.66CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.17, < 4.4.183CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.9.188CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.114CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.37CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.99%
Probability of exploitation in next 30 days
EPSS Percentile
58.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-46781 · Apr 30, 2019
This CVE's current EPSS score of 0.0099 is in the 90th percentile among its peer group of 1,516 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-1062.rt56.1022.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-1062.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: kernel-0:3.10.0-693.62.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: kernel-0:3.10.0-693.62.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-693.62.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.5 Extended Update SupportFixed in: kernel-0:3.10.0-862.48.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: kernel-0:3.10.0-957.43.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-147.rt24.93.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-147.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.62.1.rt56.659.el6rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSFixed in: kernel-0:3.10.0-957.43.1.el7
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt

Vendor Advisories (1)

redhatCVE-2019-11599Moderate

kernel: fix race condition between mmget_not_zero()/get_task_mm() and core dumping

Apr 19, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-07/msg00014.html
Third Party AdvisoryVDB Entry
lists.opensuse.org / opensuse-security-announce/2019-07/msg00025.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/152663/Linux-Missing-Lockdown.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:2029
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:2043
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:3309
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:3517
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2020:0100
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2020:0103
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2020:0179
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2020:0543
Third Party AdvisoryVDB Entry
bugs.chromium.org / p/project-zero/issues/detail
ExploitMailing ListThird Party Advisory
cdn.kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.14.114
Mailing ListVendor Advisory
cdn.kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.19.37
Mailing ListVendor Advisory
cdn.kernel.org / pub/linux/kernel/v5.x/ChangeLog-5.0.10
Mailing ListVendor Advisory
github.com / torvalds/linux/commit/04f5866e41fb70690e28397487d8bd8eea7d712a
PatchThird Party Advisory
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Mailing ListPatchVendor Advisory
lists.debian.org / debian-lts-announce/2019/05/msg00041.html
Exploit
lists.debian.org / debian-lts-announce/2019/05/msg00042.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2019/06/msg00011.html
Broken Link
seclists.org / bugtraq/2019/Jul/33
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Jun/26
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20190517-0002
Third Party Advisory
security.netapp.com / advisory/ntap-20200608-0001
Third Party AdvisoryVDB Entry
support.f5.com / csp/article/K51674118
Third Party Advisory
support.f5.com / csp/article/K51674118
Third Party Advisory
usn.ubuntu.com / 4069-1
Third Party Advisory
usn.ubuntu.com / 4069-2
Third Party AdvisoryVDB Entry
usn.ubuntu.com / 4095-1
Third Party AdvisoryVDB Entry
usn.ubuntu.com / 4115-1
Third Party AdvisoryVDB Entry
usn.ubuntu.com / 4118-1
Third Party AdvisoryVDB Entry
debian.org / security/2019/dsa-4465
Third Party Advisory
exploit-db.com / exploits/46781
ExploitThird Party AdvisoryVDB Entry
oracle.com / security-alerts/cpuApr2021.html
Third Party Advisory
openwall.com / lists/oss-security/2019/04/29/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/04/29/2
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/04/30/1
Mailing ListThird Party Advisory
securityfocus.com / bid/108113
Third Party AdvisoryVDB Entry