CVE-2019-14835

Advisory lineage Upstream: 0 Downstream: 50
Modified
Published: 17 Sept 2019, 15:09
Last modified:05 Aug 2024, 00:26

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.07% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

17 Sept 2019, 15:09
Published
Vulnerability first disclosed
05 Aug 2024, 00:26
Last Modified
Vulnerability information updated

Description

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.0HIGHScore: 7.2CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.07% Percentile: 22%

Techniques & Countermeasures

  • CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

    The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 16.04 | 18.04 | 19.04

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • fedoraprojectfedora

    29 | 30

  • huaweiimanager_neteco

    v600r009c00 | v600r009c10spc200

  • huaweiimanager neteco 6000

    v600r008c10spc300 | v600r008c20

  • huaweimanageone

    6.5.0 | 6.5.0.spc100.b210 | 6.5.1rc1.b060 | 6.5.1rc1.b080 | 6.5.rc2.b050

  • linux kernellinux kernel

    from version 2.6.34 to 5.2.x

  • linuxlinux_kernel

    ≥ 2.6.34, < 3.16.74 | ≥ 4.4, < 4.4.193 | ≥ 4.9, < 4.9.193 | ≥ 4.14, < 4.14.144 | ≥ 4.19, < 4.19.73 | ≥ 5.2, < 5.2.15 | 5.3

  • netappaff_a700s

    na

  • netappdata_availability_services

    na

  • netapph300e_firmware

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e_firmware

    na

  • netapph500s_firmware

    na

  • netapph610s_firmware

    na

  • netapph700e_firmware

    na

  • netapph700s_firmware

    na

  • netapphci_management_node

    na

  • netappservice_processor

    na

  • netappsolidfire

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • opensuseleap

    15.0 | 15.1

  • redhatenterprise_linux

    8.0

  • redhatenterprise_linux_desktop

    6.0 | 7.0

  • redhatenterprise_linux_eus

    7.5 | 7.6 | 7.7

  • redhatenterprise_linux_for_real_time

    7 | 8

  • redhatenterprise_linux_server

    6.0 | 7.0 | 7.6

  • redhatenterprise_linux_server_aus

    6.5 | 6.6 | 7.2 | 7.3 | 7.4 | 7.6 | 7.7

  • redhatenterprise_linux_server_tus

    7.2 | 7.3 | 7.4 | 7.6 | 7.7

  • redhatenterprise_linux_workstation

    6.0 | 7.0

  • redhatopenshift_container_platform

    3.11

  • redhatvirtualization

    4.0

  • redhatvirtualization_host

    4.0

References (40)