CVE-2019-19241 is a privilege escalation vulnerability in the Linux kernel prior to version 5.4.2, specifically affecting the io_uring feature. It allows an unprivileged attacker to execute operations with UID 0 and full capabilities, such as adding an IPv4 address to the loopback interface, by exploiting how IORING_OP_SENDMSG operations are handled by kernel worker threads. This vulnerability is rated as HIGH severity (CVSS 7.8), indicating a local attack vector with low complexity and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or widespread community discussion, a public exploit (EDB-47779) exists, demonstrating its feasibility.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.4.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.