5.5

CVE-2018-19407

The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where ioapic is uninitialized.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 4.19.2
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.374
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html
https://usn.ubuntu.com/3871-1/
Third Party Advisory
https://usn.ubuntu.com/3871-3/
Third Party Advisory
https://usn.ubuntu.com/3871-4/
Third Party Advisory
https://usn.ubuntu.com/3871-5/
Third Party Advisory
https://usn.ubuntu.com/3879-1/
Third Party Advisory
https://usn.ubuntu.com/3879-2/
Third Party Advisory
https://usn.ubuntu.com/3872-1/
Third Party Advisory
https://usn.ubuntu.com/3878-1/
Third Party Advisory
https://usn.ubuntu.com/3878-2/
Third Party Advisory
http://www.securityfocus.com/bid/105987
Third Party Advisory
VDB Entry
https://lkml.org/lkml/2018/11/20/580
Patch
Third Party Advisory