FlawAtlas
Search the atlas
CVE-2019-19449 High

CVE-2019-19449

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).

Exploit probability 2.0%
Published December 8, 2019
Required by Not available
Last source change March 14, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-19449

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).

View original source

05 / REFERENCES

Further evidence