CVE-2019-19449

HIGH

Linux kernel 5.0.21 - Info Disclosure

Title source: llm
STIX 2.1

Description

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200103-0001/

Scores

CVSS v3 7.8
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-125
Status published
Products (1)
linux/linux_kernel 5.0.21
Published Dec 08, 2019
Tracked Since Feb 18, 2026