CVE-2019-19767: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 2.1% chance of exploitation in the next 30 days.

The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.

Affected products

  • Linux Linux Kernel: before 5.4.2 (fixed in 5.4.2)

Published 2019-12-12. Last modified 2026-06-17.