Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-19039

21
FAUCET Score

CVE-2019-19039 is a medium-severity information disclosure vulnerability affecting the Linux kernel, specifically the btrfs filesystem, in versions through 5.3.12. It allows local users to potentially obtain sensitive register information via the dmesg program due to an improper call to btrfs_print_leaf in a specific error case. The vulnerability has a CVSS score of 5.5, indicating a local attack vector with low complexity and high confidentiality impact, but no integrity or availability impact. Despite the potential for information disclosure, the BTRFS development team disputes its classification as a vulnerability, citing existing kernel controls for dmesg access and the common use of similar debugging macros. There is no known active exploitation, public exploit code, or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.3.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.70%
Probability of exploitation in next 30 days
EPSS Percentile
49.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0070 is in the 55th percentile among its peer group of 5,765 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2019-19039Low

kernel: information disclosure in __btrfs_free_extent in fs/btrfs/extent-tree.c

Nov 20, 2019

References

github.com / bobfuzzer/CVE/tree/master/CVE-2019-19039
ExploitThird Party Advisory
lists.debian.org / debian-lts-announce/2020/12/msg00015.html
Mailing ListThird Party Advisory
usn.ubuntu.com / 4414-1
Third Party Advisory