CVE-2019-5188 is a code execution vulnerability in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4, affecting products from vendors like Canonical, Debian, and NetApp. An attacker can exploit this by corrupting an ext4 partition, leading to an out-of-bounds write on the stack and subsequent code execution. With a CVSS score of 6.7 (Medium), it requires high privileges for exploitation but can result in high impact to confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.43.3, <= 1.45.4CPE matchmatch criteria | cpe:2.3:a:e2fsprogs_project:e2fsprogs:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-5188
Jan 12, 2021A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Jan 14, 2020e2fsprogs: Out-of-bounds write in e2fsck/rehash.c
Jan 7, 2020