Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-5188

23
FAUCET Score

CVE-2019-5188 is a code execution vulnerability in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4, affecting products from vendors like Canonical, Debian, and NetApp. An attacker can exploit this by corrupting an ext4 partition, leading to an out-of-bounds write on the stack and subsequent code execution. With a CVSS score of 6.7 (Medium), it requires high privileges for exploitation but can result in high impact to confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness of its potential.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.43.3, <= 1.45.4CPE matchmatch criteria
cpe:2.3:a:e2fsprogs_project:e2fsprogs:*:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.03%
Probability of exploitation in next 30 days
EPSS Percentile
60.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0103 is in the 98th percentile among its peer group of 3,720 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: cm1 e2fsprogs 1.44.6-4 on CBL Mariner 1.0Fixed in: 1.44.6-4
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.44.6-4
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.44.6-4
microsoftpatch availablevia msrc
Product: 17066-16820Fixed in: 1.44.6-4
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift DoFixed in: openshiftdo/odo-init-image-rhel7:1.1.3-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: e2fsprogs-0:1.42.9-19.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: e2fsprogs-0:1.45.4-3.el8
View patch

Vendor Advisories (3)

microsoft2021-Jan/CVE-2019-5188

CVE-2019-5188

Jan 12, 2021
microsoft2020-Jan/CVE-2019-5188Moderate

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

Jan 14, 2020
redhatCVE-2019-5188Moderate

e2fsprogs: Out-of-bounds write in e2fsck/rehash.c

Jan 7, 2020

References

lists.opensuse.org / opensuse-security-announce/2020-02/msg00004.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/03/msg00030.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/07/msg00021.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY
security.netapp.com / advisory/ntap-20220506-0001
Third Party Advisory
talosintelligence.com / vulnerability_reports/TALOS-2019-0973
ExploitThird Party Advisory
usn.ubuntu.com / 4249-1
Third Party Advisory