Tracker / CVE-2019-14835
CVE-2019-14835
Alta 7.8
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
Prodotti e versioni affette
| canonical | ubuntu_linux |
|---|---|
| debian | debian_linux |
| fedoraproject | fedora |
| huawei | imanager_neteco |
| huawei | imanager_neteco_6000 |
| huawei | manageone |
| linux | linux_kernel |
| linux | linux_kernel · 2.6.34 → 3.16.74 |
| linux | linux_kernel · 4.14 → 4.14.144 |
| linux | linux_kernel · 4.19 → 4.19.73 |
| linux | linux_kernel · 4.4 → 4.4.193 |
| linux | linux_kernel · 4.9 → 4.9.193 |
| linux | linux_kernel · 5.2 → 5.2.15 |
| netapp | aff_a700s_firmware |
| netapp | data_availability_services |
| netapp | h300e_firmware |
| netapp | h300s_firmware |
| netapp | h410c_firmware |
| netapp | h410s_firmware |
| netapp | h500e_firmware |
| netapp | h500s_firmware |
| netapp | h610s_firmware |
| netapp | h700e_firmware |
| netapp | h700s_firmware |
| netapp | hci_management_node |
| netapp | service_processor |
| netapp | solidfire |
| netapp | steelstore_cloud_integrated_storage |
| opensuse | leap |
| redhat | enterprise_linux |
| redhat | enterprise_linux_desktop |
| redhat | enterprise_linux_eus |
| redhat | enterprise_linux_for_real_time |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_tus |
| redhat | enterprise_linux_workstation |
| redhat | openshift_container_platform |
| redhat | virtualization |
| redhat | virtualization_host |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.