PT-2019-4485 · Linux+5 · Linux Kernel+5

Published

2019-06-21

·

Updated

2025-09-29

·

CVE-2019-19447

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 5.0.21
Description The issue is related to a use-after-free in the ext4 put super function in fs/ext4/super.c, which is connected to the dump orphan list function in the same file. This can occur when mounting a crafted ext4 filesystem image, performing certain operations, and then unmounting it. The exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel version 5.0.21, consider disabling the ext4 put super function as a temporary workaround until a patch is available. Restrict access to the fs/ext4/super.c module to minimize the risk of exploitation. Avoid using crafted ext4 filesystem images until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4431
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_13589
ALSA-2025_13590
ALSA-2025_16880
ALT-PU-2019-2120
ALT-PU-2019-2311
BDU:2020-00305
CESA-2020_4060
CESA-2020_4431
CESA-2020_4609
CVE-2019-19447
DLA-2114-1
DLA-2241-1
DLA-2241-2
ELSA-2020-4060
ELSA-2020-4431
ELSA-2020-5804
ELSA-2021-9002
OPENSUSE-SU-2020:0336-1
OPENSUSE-SU-2020_0336-1
RHSA-2020:2104
RHSA-2020:4060
RHSA-2020:4062
RHSA-2020:4431
RHSA-2020:4609
RHSA-2020:5206
RHSA-2020:5430
RHSA-2020:5656
RHSA-2020_4060
RHSA-2020_4062
RHSA-2020_4431
RHSA-2020_4609
SUSE-SU-2020:0093-1
SUSE-SU-2020:0511-1
SUSE-SU-2020:0559-1
SUSE-SU-2020:0560-1
SUSE-SU-2020:0580-1
SUSE-SU-2020:0584-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1255-1
SUSE-SU-2020:1275-1
SUSE-SU-2020:1663-1
SUSE-SU-2020:2491-1
SUSE-SU-2020:2492-1
SUSE-SU-2020:2497-1
SUSE-SU-2020:2498-1
SUSE-SU-2020:2505-1
SUSE-SU-2020:2506-1
SUSE-SU-2020:2513-1
SUSE-SU-2020:2526-1
SUSE-SU-2020_1663-1
SUSE-SU-2020_2492-1
SUSE-SU-2020_2497-1
SUSE-SU-2020_2498-1
SUSE-SU-2020_2505-1
SUSE-SU-2020_2513-1
SUSE-SU-2020_2526-1

Affected Products

Alt Linux
Almalinux
Centos
Linux Kernel
Red Hat
Suse