Back to search
CVE-2019-6974
Published: Feb 15, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.chromium.org/p/project-zero/issues/detail?id=1765
x_refsource_MISC
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.99
x_refsource_MISC
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.21
x_refsource_MISC
46388
exploit
x_refsource_EXPLOIT-DB
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.20.8
x_refsource_MISC
107127
vdb-entry
x_refsource_BID
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.156
x_refsource_MISC
[debian-lts-announce] 20190327 [SECURITY] [DLA 1731-1] linux security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20190401 [SECURITY] [DLA 1731-2] linux regression update
mailing-list
x_refsource_MLIST
USN-3932-1
vendor-advisory
x_refsource_UBUNTU
USN-3932-2
vendor-advisory
x_refsource_UBUNTU
USN-3930-1
vendor-advisory
x_refsource_UBUNTU
USN-3931-1
vendor-advisory
x_refsource_UBUNTU
USN-3933-2
vendor-advisory
x_refsource_UBUNTU
USN-3931-2
vendor-advisory
x_refsource_UBUNTU
USN-3930-2
vendor-advisory
x_refsource_UBUNTU
USN-3933-1
vendor-advisory
x_refsource_UBUNTU
https://support.f5.com/csp/article/K11186236
x_refsource_CONFIRM
RHSA-2019:0833
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0818
vendor-advisory
x_refsource_REDHAT
[debian-lts-announce] 20190503 [SECURITY] [DLA 1771-1] linux-4.9 security update
mailing-list
x_refsource_MLIST
RHBA-2019:0959
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2809
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3967
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0103
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now