Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-19602

21
FAUCET Score

CVE-2019-19602 is a memory corruption vulnerability in the Linux kernel (before version 5.4.2) affecting x86 architectures when compiled with GCC 9, specifically impacting Canonical and general Linux distributions. The flaw stems from incorrect caching of fpu_fpregs_owner_ctx, potentially leading to a denial of service or other unspecified impacts, as demonstrated by issues with Go 1.14 prereleases. With a CVSS score of 6.1 (Medium), this vulnerability requires local access and low privileges, but has a high impact on confidentiality and low impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog. Community discussion and media coverage are minimal, with only one article mentioning it in the context of Tails 4.2 security fixes.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.4.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
19.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.61%
Probability of exploitation in next 30 days
EPSS Percentile
45.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0061 is in the 94th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-240.el8
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt

Vendor Advisories (1)

redhatCVE-2019-19602Moderate

kernel: cached use of fpu_fpregs_owner_ctx in arch/x86/include/asm/fpu/internal.h can lead to DoS

Nov 26, 2019

References

bugzilla.kernel.org / show_bug.cgi
Issue TrackingThird Party Advisory
cdn.kernel.org / pub/linux/kernel/v5.x/ChangeLog-5.4.2
Release NotesVendor Advisory
github.com / golang/go/issues/35777
Issue TrackingThird Party Advisory
github.com / torvalds/linux/commit/59c4bd853abcea95eccc167a7d7fd5f1a5f47b98
ExploitThird Party Advisory
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
ExploitVendor Advisory
security.netapp.com / advisory/ntap-20200103-0001
Third Party Advisory
usn.ubuntu.com / 4284-1
Third Party Advisory