CVE-2019-19602 is a memory corruption vulnerability in the Linux kernel (before version 5.4.2) affecting x86 architectures when compiled with GCC 9, specifically impacting Canonical and general Linux distributions. The flaw stems from incorrect caching of fpu_fpregs_owner_ctx, potentially leading to a denial of service or other unspecified impacts, as demonstrated by issues with Go 1.14 prereleases. With a CVSS score of 6.1 (Medium), this vulnerability requires local access and low privileges, but has a high impact on confidentiality and low impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog. Community discussion and media coverage are minimal, with only one article mentioning it in the context of Tails 4.2 security fixes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.4.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
19.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.