CVE Database
/

CVE-2019-14821

Back to search

CVE-2019-14821

Published: Sep 19, 2019

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

7.5

HIGH

Description

An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.

VendorProductVersions

Linux

Kernel

affected
all through 5.3

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

High

Availability

High

References

FEDORA-2019-15e141c6a7
vendor-advisory
x_refsource_FEDORA
DSA-4531
vendor-advisory
x_refsource_DEBIAN
FEDORA-2019-a570a92d5a
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:2307
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2308
vendor-advisory
x_refsource_SUSE
USN-4157-1
vendor-advisory
x_refsource_UBUNTU
USN-4162-1
vendor-advisory
x_refsource_UBUNTU
USN-4157-2
vendor-advisory
x_refsource_UBUNTU
USN-4163-1
vendor-advisory
x_refsource_UBUNTU
USN-4163-2
vendor-advisory
x_refsource_UBUNTU
USN-4162-2
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:3309
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3517
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3978
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3979
vendor-advisory
x_refsource_REDHAT
RHSA-2019:4154
vendor-advisory
x_refsource_REDHAT
RHSA-2019:4256
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0027
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0204
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now