CVE-2019-19039Log File Information Exposure in Linux

Severity
5.5MEDIUMNVD
OSV4.1
EPSS
0.4%
top 37.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateMay 24

Description

__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team disputes this issues as not being a vulnerability because “1) The kernel provide facilities to restrict access to dmesg - dmesg_restrict=1 sysctl option. So it's really up to the system administrator to judge whether dmesg

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Debianlinux/linux_kernel< 5.6.7-1+3
Ubuntulinux/linux_kernel< 4.15.0-109.110
NVDlinux/linux_kernel5.3.12
debiandebian/linux< linux 5.6.7-1 (bookworm)

Also affects: Debian Linux 9.0, Ubuntu Linux 14.04, 16.04, 18.04

🔴Vulnerability Details

3
GHSA
GHSA-g3r9-j55g-jg8j: __btrfs_free_extent in fs/btrfs/extent-tree2022-05-24
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2020-07-06
OSV
CVE-2019-19039: __btrfs_free_extent in fs/btrfs/extent-tree2019-11-21

📋Vendor Advisories

3
Ubuntu
Linux kernel vulnerabilities2020-07-06
Red Hat
kernel: information disclosure in __btrfs_free_extent in fs/btrfs/extent-tree.c2019-11-20
Debian
CVE-2019-19039: linux - __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12...2019

💬Community

2
Bugzilla
CVE-2019-19039 kernel: information disclosure in __btrfs_free_extent in fs/btrfs/extent-tree.c [fedora-all]2019-11-22
Bugzilla
CVE-2019-19039 kernel: information disclosure in __btrfs_free_extent in fs/btrfs/extent-tree.c2019-11-22