8.1
CVE-2019-6974
- EPSS 7.22%
- Published 15.02.2019 15:29:00
- Last modified 21.11.2024 04:47:20
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
Data is provided by the National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.10 < 3.16.64
Linux ≫ Linux Kernel Version >= 3.17 < 3.18.136
Linux ≫ Linux Kernel Version >= 3.19 < 4.4.176
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.156
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.99
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.21
Linux ≫ Linux Kernel Version >= 4.20 < 4.20.8
Debian ≫ Debian Linux Version8.0
Canonical ≫ Ubuntu Linux Version12.04 SwEditionesm
Canonical ≫ Ubuntu Linux Version14.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version16.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version18.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version18.10
F5 ≫ Big-ip Access Policy Manager Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Access Policy Manager Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Access Policy Manager Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Advanced Firewall Manager Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Advanced Firewall Manager Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Advanced Firewall Manager Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Analytics Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Analytics Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Analytics Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Application Acceleration Manager Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Application Acceleration Manager Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Application Acceleration Manager Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Application Security Manager Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Application Security Manager Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Application Security Manager Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Edge Gateway Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Edge Gateway Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Edge Gateway Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Fraud Protection Service Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Fraud Protection Service Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Fraud Protection Service Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Global Traffic Manager Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Global Traffic Manager Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Global Traffic Manager Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Link Controller Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Link Controller Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Link Controller Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Local Traffic Manager Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Local Traffic Manager Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Local Traffic Manager Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Policy Enforcement Manager Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Policy Enforcement Manager Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Policy Enforcement Manager Version >= 15.0.0 < 15.1.0
F5 ≫ Big-ip Webaccelerator Version >= 13.0.0 <= 13.1.1
F5 ≫ Big-ip Webaccelerator Version >= 14.0.0 <= 14.1.0
F5 ≫ Big-ip Webaccelerator Version >= 15.0.0 < 15.1.0
Redhat ≫ Openshift Container Platform Version3.11
Redhat ≫ Enterprise Linux Version7.0
Redhat ≫ Enterprise Linux Desktop Version7.0
Redhat ≫ Enterprise Linux Eus Version7.5
Redhat ≫ Enterprise Linux Server Version7.0
Redhat ≫ Enterprise Linux Server Aus Version7.4
Redhat ≫ Enterprise Linux Server Aus Version7.6
Redhat ≫ Enterprise Linux Server Eus Version7.6
Redhat ≫ Enterprise Linux Server Tus Version7.4
Redhat ≫ Enterprise Linux Server Tus Version7.6
Redhat ≫ Enterprise Linux Workstation Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 7.22% | 0.913 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.