UBUNTU-CVE-2019-19448

Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 08 Dec 2019, 02:15
Last modified:20 May 2026, 16:04

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
3.1 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Dec 2019, 02:15
Published
Vulnerability first disclosed
20 May 2026, 16:04
Last Modified
Vulnerability information updated

Description

In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Systems

  • ubuntulinux

    all | < 4.4.0-190.220 | < 4.15.0-121.123 | < 5.4.0-48.52

  • ubuntulinux-aws

    < 4.4.0-1078.82 | < 4.4.0-1114.127 | < 4.15.0-1086.91 | < 5.4.0-1025.25

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1025.25~18.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2030.31 | all | < 5.4.0-1069.73+fips2

  • ubuntulinux-aws-hwe

    < 4.15.0-1085.90~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1098.109~14.04.1 | < 4.15.0-1098.109~16.04.1 | all | < 5.4.0-1026.26

  • ubuntulinux-azure-4.15

    < 4.15.0-1099.110

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1026.26~18.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2012.14 | all | < 5.4.0-1073.76+fips1

  • ubuntulinux-fips

    < 4.4.0-1046.51 | all | < 4.15.0-1044.50

  • ubuntulinux-gcp

    < 4.15.0-1086.98~16.04.1 | all | < 5.4.0-1025.25

  • ubuntulinux-gcp-4.15

    < 4.15.0-1086.98

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1025.25~18.04.1

  • ubuntulinux-gcp-edge

    all

  • ubuntulinux-gcp-fips

    all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-gke-4.15

    < 4.15.0-1072.76

  • ubuntulinux-hwe

    < 4.15.0-120.122~16.04.1 | all

  • ubuntulinux-hwe-5.4

    < 5.4.0-48.52~18.04.1

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    < 4.4.0-1080.87 | < 4.15.0-1077.79 | < 5.4.0-1024.24

  • ubuntulinux-lts-xenial

    < 4.4.0-190.220~14.04.1

  • ubuntulinux-nvidia

    all

  • ubuntulinux-oem

    < 4.15.0-1099.109

  • ubuntulinux-oem-5.6

    all

  • ubuntulinux-oracle

    < 4.15.0-1056.61~16.04.1 | < 4.15.0-1057.62 | < 5.4.0-1025.25

  • ubuntulinux-oracle-5.0

    all

  • ubuntulinux-oracle-5.3

    all

  • ubuntulinux-oracle-5.4

    < 5.4.0-1025.25~18.04.1

  • ubuntulinux-raspi

    < 5.4.0-1019.21

  • ubuntulinux-raspi-5.4

    < 5.4.0-1019.21~18.04.1

  • ubuntulinux-raspi-realtime

    all

  • ubuntulinux-raspi2

    < 4.4.0-1139.148 | < 4.15.0-1073.78 | all

  • ubuntulinux-realtime

    all

  • ubuntulinux-riscv

    < 5.4.0-34.38

  • ubuntulinux-snapdragon

    < 4.4.0-1143.152 | < 4.15.0-1089.98

References (4)