Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-12448

26
FAUCET Score

CVE-2019-12448 is a high-severity race condition vulnerability affecting GNOME gvfs versions 1.29.4 through 1.41.2, stemming from the admin backend's failure to implement query_info_on_read/write. This flaw, with a CVSS score of 8.1, allows for high impact to confidentiality, integrity, and availability with a network-based attack of high complexity. Despite its severity, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.29.4, <= 1.41.2CPE matchmatch criteria
cpe:2.3:a:gnome:gvfs:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.1HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.75%
Probability of exploitation in next 30 days
EPSS Percentile
75.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0175 is in the 33rd percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mutter-0:3.32.2-34.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nautilus-0:3.28.1-12.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: vala-0:0.40.19-1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: vinagre-0:3.22.0-21.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: accountsservice-0:0.6.50-8.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: appstream-data-0:8-20191129.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: baobab-0:3.28.0-4.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: clutter-0:1.26.2-8.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: evince-0:3.28.4-4.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gdm-1:3.28.3-29.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gjs-0:1.56.2-4.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-boxes-0:3.28.5-8.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-control-center-0:3.28.2-19.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-menus-0:3.13.3-11.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-online-accounts-0:3.28.2-1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-remote-desktop-0:0.1.6-8.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-session-0:3.28.1-8.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-settings-daemon-0:3.32.0-9.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-shell-0:3.32.2-14.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-software-0:3.30.6-3.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-terminal-0:3.28.3-1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnome-tweaks-0:3.28.1-7.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gsettings-desktop-schemas-0:3.32.0-4.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gtk3-0:3.22.30-5.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gvfs-0:1.36.2-8.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: LibRaw-0:0.19.5-1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libvncserver-0:0.9.11-14.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libxslt-0:1.1.32-4.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mozjs52-0:52.9.0-2.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mozjs60-0:60.9.0-4.el8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: gvfs

Vendor Advisories (1)

redhatCVE-2019-12448Moderate

gvfs: race condition in daemon/gvfsbackendadmin.c due to admin backend not implementing query_info_on_read/write

May 29, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-07/msg00008.html
lists.opensuse.org / opensuse-security-announce/2019-07/msg00009.html
gitlab.gnome.org / GNOME/gvfs/commit/764e9af7522e3096c0f44613c330377d31c9bbb5
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FP6BFQUPQRVRRFIYHFWWB6RHJNEB4LGQ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/M2DQVOL5H5BVLXYCEB763DCIYJQ7ZUQ2
usn.ubuntu.com / 4053-1
openwall.com / lists/oss-security/2019/07/09/3