imPC@ndo IT

Tracker / CVE-2019-14821

CVE-2019-14821

High 8.8

An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
linux linux_kernel
linux linux_kernel · 2.6.27 → 3.15.10
linux linux_kernel · 3.16 → 3.16.74
linux linux_kernel · 4.14 → 4.14.146
linux linux_kernel · 4.19 → 4.19.75
linux linux_kernel · 4.4 → 4.4.194
linux linux_kernel · 4.9 → 4.9.194
linux linux_kernel · 5.2 → 5.2.17
linux linux_kernel · 5.3 → 5.3.1
netapp aff_a700s_firmware
netapp data_availability_services
netapp h300e_firmware
netapp h300s_firmware
netapp h410c_firmware
netapp h410s_firmware
netapp h500e_firmware
netapp h500s_firmware
netapp h610s_firmware
netapp h700e_firmware
netapp h700s_firmware
netapp hci_management_node
netapp solidfire
opensuse leap
oracle sd-wan_edge
redhat enterprise_linux
redhat enterprise_linux_desktop
redhat enterprise_linux_eus
redhat enterprise_linux_for_real_time
redhat enterprise_linux_server
redhat enterprise_linux_server_aus
redhat enterprise_linux_server_tus
redhat enterprise_linux_workstation
redhat virtualization_host

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References