7.8
CVE-2019-14835
- EPSS 0.63%
- Veröffentlicht 17.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:27
- Erkennungen
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.34 < 3.16.74
Linux ≫ Linux Kernel Version >= 4.4 < 4.4.193
Linux ≫ Linux Kernel Version >= 4.9 < 4.9.193
Linux ≫ Linux Kernel Version >= 4.14 < 4.14.144
Linux ≫ Linux Kernel Version >= 4.19 < 4.19.73
Linux ≫ Linux Kernel Version >= 5.2 < 5.2.15
Linux ≫ Linux Kernel Version 5.3
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Netapp ≫ Aff A700s Firmware Version -
Netapp ≫ H410c Firmware Version -
Netapp ≫ H610s Firmware Version -
Netapp ≫ H300s Firmware Version -
Netapp ≫ H500s Firmware Version -
Netapp ≫ H700s Firmware Version -
Netapp ≫ H300e Firmware Version -
Netapp ≫ H500e Firmware Version -
Netapp ≫ H700e Firmware Version -
Netapp ≫ H410s Firmware Version -
Netapp ≫ Data Availability Services Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Service Processor Version -
Netapp ≫ Steelstore Cloud Integrated Storage Version -
Redhat ≫ Openshift Container Platform Version 3.11
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Redhat ≫ Enterprise Linux For Real Time Version 7
Redhat ≫ Enterprise Linux For Real Time Version 8
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 6.5
Redhat ≫ Enterprise Linux Server Aus Version 6.6
Redhat ≫ Enterprise Linux Server Aus Version 7.2
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 7.7
Redhat ≫ Enterprise Linux Server Tus Version 7.2
Redhat ≫ Enterprise Linux Server Tus Version 7.3
Redhat ≫ Enterprise Linux Server Tus Version 7.4
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Redhat ≫ Virtualization Version 4.0
Redhat ≫ Virtualization Host Version 4.0
Huawei ≫ Imanager Neteco Version v600r009c00
Huawei ≫ Imanager Neteco Version v600r009c10spc200
Huawei ≫ Imanager Neteco 6000 Version v600r008c10spc300
Huawei ≫ Imanager Neteco 6000 Version v600r008c20
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.453 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| RedHat | 7.2 | 0.6 | 6 |
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://access.redhat.com/errata/RHBA-2019:2824
http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
https://seclists.org/bugtraq/2019/Nov/11
http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html
https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html
https://lists.debian.org/debian-lts-announce/2019/10/msg00000.html
https://seclists.org/bugtraq/2019/Sep/41
https://www.debian.org/security/2019/dsa-4531
https://access.redhat.com/errata/RHSA-2019:2899
https://access.redhat.com/errata/RHSA-2019:2900
https://usn.ubuntu.com/4135-1/
https://usn.ubuntu.com/4135-2/
http://packetstormsecurity.com/files/154572/Kernel-Live-Patch-Security-Notice-LSN-0056-1.html
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-qemu-en
http://www.openwall.com/lists/oss-security/2019/09/24/1
http://www.openwall.com/lists/oss-security/2019/10/03/1
http://www.openwall.com/lists/oss-security/2019/10/09/3
http://www.openwall.com/lists/oss-security/2019/10/09/7
https://access.redhat.com/errata/RHSA-2019:2827
https://access.redhat.com/errata/RHSA-2019:2828
https://access.redhat.com/errata/RHSA-2019:2829
https://access.redhat.com/errata/RHSA-2019:2830
https://access.redhat.com/errata/RHSA-2019:2854
https://access.redhat.com/errata/RHSA-2019:2862
https://access.redhat.com/errata/RHSA-2019:2863
https://access.redhat.com/errata/RHSA-2019:2864
https://access.redhat.com/errata/RHSA-2019:2865
https://access.redhat.com/errata/RHSA-2019:2866
https://access.redhat.com/errata/RHSA-2019:2867
https://access.redhat.com/errata/RHSA-2019:2869
https://access.redhat.com/errata/RHSA-2019:2889
https://access.redhat.com/errata/RHSA-2019:2901
https://access.redhat.com/errata/RHSA-2019:2924
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14835
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQFY6JYFIQ2VFQ7QCSXPWTUL5ZDNCJL5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3QNMPENPFEGVTOFPSNOBL7JEIJS25P/
https://security.netapp.com/advisory/ntap-20191031-0005/
https://www.openwall.com/lists/oss-security/2019/09/17/1