CVE-2019-19770: Linux Kernel
High severity, CVSS 8.2. EPSS: 2.4% chance of exploitation in the next 30 days.
In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file). NOTE: Linux kernel developers dispute this issue as not being an issue with debugfs, instead this is an issue with misuse of debugfs within blktrace
Affected products
- Linux Linux Kernel: up to and including 4.19.83
Published 2019-12-12. Last modified 2026-06-17.