CVE-2019-19377: Linux Kernel

High severity, CVSS 7.8. EPSS: 3.4% chance of exploitation in the next 30 days.

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.

Affected products

  • Linux Linux Kernel: from 2.6.12, before 4.19.156 (fixed in 4.19.156); from 4.20, before 5.4.33 (fixed in 5.4.33); from 5.5.0, before 5.5.18 (fixed in 5.5.18); from 5.6, before 5.6.5 (fixed in 5.6.5)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Solidfire Baseboard Management Controller: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified

Published 2019-11-29. Last modified 2026-06-17.