CVE-2019-19448 is a use-after-free vulnerability in the Linux kernel's btrfs filesystem, specifically affecting versions 5.0.21 and 5.3.11, and impacting products from Canonical, Debian, Linux, and NetApp. This flaw, rated 7.8 HIGH, can be triggered by mounting a specially crafted btrfs image, performing certain operations, and then invoking a syncfs system call, leading to high confidentiality, integrity, and availability impacts. While no public exploits or Metasploit/Nuclei modules are available, and there's minimal community discussion or media coverage, the vulnerability's nature suggests a potential for local exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.31, < 4.4.233CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5.0, < 4.9.233CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.194CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.141CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.60CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.