Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-19241

36
FAUCET Score

CVE-2019-19241 is a privilege escalation vulnerability in the Linux kernel prior to version 5.4.2, specifically affecting the io_uring feature. It allows an unprivileged attacker to execute operations with UID 0 and full capabilities, such as adding an IPv4 address to the loopback interface, by exploiting how IORING_OP_SENDMSG operations are handled by kernel worker threads. This vulnerability is rated as HIGH severity (CVSS 7.8), indicating a local attack vector with low complexity and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or widespread community discussion, a public exploit (EDB-47779) exists, demonstrating its feasibility.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.4.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.09%
Probability of exploitation in next 30 days
EPSS Percentile
61.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-47779 · Dec 16, 2019
This CVE's current EPSS score of 0.0109 is in the 93rd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2019-19241Moderate

kernel: privilege escalation via io_uring offload of sendmsg() onto kernel thread with kernel creds

Nov 25, 2019

References

bugs.chromium.org / p/project-zero/issues/detail
Mailing ListThird Party Advisory
cdn.kernel.org / pub/linux/kernel/v5.x/ChangeLog-5.4.2
Mailing ListVendor Advisory
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
PatchVendor Advisory
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
PatchVendor Advisory
security.netapp.com / advisory/ntap-20200103-0001
usn.ubuntu.com / 4284-1