CVE-2019-11487: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: before 4.4.216 (fixed in 4.4.216); from 4.5, before 4.9.181 (fixed in 4.9.181); from 4.10, before 4.14.116 (fixed in 4.14.116); from 4.15, before 4.19.39 (fixed in 4.19.39); from 4.20, before 5.0.12 (fixed in 5.0.12); version 5.1 only

Published 2019-04-23. Last modified 2026-06-17.