Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-19448

25
FAUCET Score

CVE-2019-19448 is a use-after-free vulnerability in the Linux kernel's btrfs filesystem, specifically affecting versions 5.0.21 and 5.3.11, and impacting products from Canonical, Debian, Linux, and NetApp. This flaw, rated 7.8 HIGH, can be triggered by mounting a specially crafted btrfs image, performing certain operations, and then invoking a syncfs system call, leading to high confidentiality, integrity, and availability impacts. While no public exploits or Metasploit/Nuclei modules are available, and there's minimal community discussion or media coverage, the vulnerability's nature suggests a potential for local exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.31, < 4.4.233CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5.0, < 4.9.233CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.194CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.141CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.60CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.14%
Probability of exploitation in next 30 days
EPSS Percentile
80.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0214 is in the 80th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2019-19448Moderate

kernel: mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c

Dec 10, 2019

References

github.com / bobfuzzer/CVE/tree/master/CVE-2019-19448
ExploitThird Party Advisory
lists.debian.org / debian-lts-announce/2020/09/msg00025.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/10/msg00032.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/10/msg00034.html
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20200103-0001
Third Party Advisory
usn.ubuntu.com / 4578-1
Third Party Advisory