Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-5489

21
FAUCET Score

CVE-2019-5489 describes a local information disclosure vulnerability in the Linux kernel's mincore() implementation (through version 4.19.13), affecting various Linux-based products including NetApp offerings. This flaw allows local attackers to observe page cache access patterns of other processes, potentially enabling the sniffing of sensitive information, with limited remote exploitation also possible via latency differences. Rated 5.5 MEDIUM (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), it has low attack complexity and requires local privileges, leading to high confidentiality impact. While not listed in CISA's KEV catalog and lacking public exploit tools like Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness of its potential.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.19.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_performance_analytics_services:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:element_software_management_node:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.5MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.77%
Probability of exploitation in next 30 days
EPSS Percentile
52.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0077 is in the 95th percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5 Extended Lifecycle SupportFixed in: kernel-0:2.6.18-439.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-754.18.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Advanced Update SupportFixed in: kernel-0:2.6.32-431.97.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Advanced Update SupportFixed in: kernel-0:2.6.32-504.82.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-1062.rt56.1022.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-1062.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt-0:4.14.0-115.12.1.el7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Advanced Update SupportFixed in: kernel-0:3.10.0-327.83.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Telco Extended Update SupportFixed in: kernel-0:3.10.0-327.83.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-327.83.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: kernel-0:3.10.0-514.71.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Telco Extended Update SupportFixed in: kernel-0:3.10.0-514.71.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-514.71.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: kernel-0:3.10.0-693.61.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: kernel-0:3.10.0-693.61.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-693.61.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.5 Extended Update SupportFixed in: kernel-0:3.10.0-862.44.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: kernel-0:3.10.0-957.35.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-147.rt24.93.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-147.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-80.15.1.el8_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.61.1.rt56.656.el6rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSFixed in: kernel-0:3.10.0-957.35.1.el7
View patch

Vendor Advisories (1)

redhatCVE-2019-5489Important

Kernel: page cache side channel attacks

Jan 6, 2019

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
PatchVendor Advisory
lists.opensuse.org / opensuse-security-announce/2019-05/msg00071.html
lists.opensuse.org / opensuse-security-announce/2019-06/msg00039.html
lists.opensuse.org / opensuse-security-announce/2019-06/msg00048.html
access.redhat.com / errata/RHSA-2019:2029
access.redhat.com / errata/RHSA-2019:2043
access.redhat.com / errata/RHSA-2019:2473
access.redhat.com / errata/RHSA-2019:2808
access.redhat.com / errata/RHSA-2019:2809
access.redhat.com / errata/RHSA-2019:2837
access.redhat.com / errata/RHSA-2019:3309
access.redhat.com / errata/RHSA-2019:3517
access.redhat.com / errata/RHSA-2019:3967
access.redhat.com / errata/RHSA-2019:4056
access.redhat.com / errata/RHSA-2019:4057
access.redhat.com / errata/RHSA-2019:4058
access.redhat.com / errata/RHSA-2019:4159
access.redhat.com / errata/RHSA-2019:4164
access.redhat.com / errata/RHSA-2019:4255
access.redhat.com / errata/RHSA-2020:0204
arxiv.org / abs/1901.01161
Third Party Advisory
bugzilla.suse.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
github.com / torvalds/linux/commit/574823bfab82d9d8fa47f422778043fbb4b4f50e
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2019/06/msg00010.html
lists.debian.org / debian-lts-announce/2019/06/msg00011.html
seclists.org / bugtraq/2019/Jun/26
security.netapp.com / advisory/ntap-20190307-0001
Third Party Advisory
debian.org / security/2019/dsa-4465
oracle.com / security-alerts/cpujul2020.html
theregister.co.uk / 2019/01/05/boffins_beat_page_cache
Technical DescriptionThird Party Advisory
huawei.com / en/psirt/security-advisories/huawei-sa-20200115-01-pagecache-en
securityfocus.com / bid/106478
Third Party AdvisoryVDB Entry