CVE-2019-14821
published 2019-09-19CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO…
PriorityP347high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.76%
51.2th percentile
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.2.17-1 (bookworm) | linux 5.2.17-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 4.4.0-166.195 | 4.4.0-166.195 |
| linux | linux_kernel | >= 0 < 4.15.0-66.75 | 4.15.0-66.75 |
| linux | linux_kernel | 2.6.27 – 3.15.10 | — |
| linux | linux_kernel | >= 3.16 < 3.16.74 | 3.16.74 |
| linux | linux_kernel | >= 4.14 < 4.14.146 | 4.14.146 |
| linux | linux_kernel | >= 4.19 < 4.19.75 | 4.19.75 |
| linux | linux_kernel | >= 4.4 < 4.4.194 | 4.4.194 |
| linux | linux_kernel | >= 4.9 < 4.9.194 | 4.9.194 |
| linux | linux_kernel | >= 5.2 < 5.2.17 | 5.2.17 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.8HIGH
vendor_oracle3.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: OS (Kernel) — CVE-2019-14821
vendor_oracle·2020-04-15·CVSS 3.9
CVE-2019-14821 [HIGH] Oracle Oracle Communications Applications Risk Matrix: OS (Kernel) — CVE-2019-14821
Oracle Oracle Communications Applications Risk Matrix: OS (Kernel) vulnerability
CVE: CVE-2019-14821
CVSS: 3.9
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2020 (APR 2020)
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2019-10-23·CVSS 7.0
CVE-2016-10906 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4163-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.
It was discovered that a race condition existed in the ARC EMAC ethernet
driver for the Linux kernel, resulting in a use-after-free vulnerability.
An attacker could use this to cause a denial of service (system crash).
(CVE-2016-10906)
It was discovered that a race condition existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel when handling certain error
conditions. A local attacker could use this to cause a denial of service
(kernel deadloc
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2019-10-23·CVSS 5.5
CVE-2018-21008 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4162-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 ESM.
It was discovered that the RSI 91x Wi-Fi driver in the Linux kernel did not
did not handle detach operations correctly, leading to a use-after-free
vulnerability. A physically proximate attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-21008)
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-10-22·CVSS 7.0
CVE-2016-10906 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ARC EMAC ethernet
driver for the Linux kernel, resulting in a use-after-free vulnerability.
An attacker could use this to cause a denial of service (system crash).
(CVE-2016-10906)
It was discovered that a race condition existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel when handling certain error
conditions. A local attacker could use this to cause a denial of service
(kernel deadlock). (CVE-2017-18232)
It was discovered that the RSI 91x Wi-Fi driver in the Linux kernel did not
did not handle detach operations correctly, leading to a use-after-free
vulnerability. A physically proximate attacker could use
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-10-22·CVSS 7.8
CVE-2019-14814 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4157-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu
18.04 LTS.
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform bounds checking when handling coalesced
MMIO write operations. A loca
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-10-22·CVSS 5.5
CVE-2018-21008 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the RSI 91x Wi-Fi driver in the Linux kernel did not
did not handle detach operations correctly, leading to a use-after-free
vulnerability. A physically proximate attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-21008)
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kerne
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-10-17·CVSS 7.8
CVE-2019-14814 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform bounds checking when handling coalesced
MMIO write operations. A local attacker with write access to /dev/kvm could
use this to cause a denial of service (system crash). (CVE-2019-14821)
Hui Peng and Mathias Payer discovered that the 91x Wi-Fi driver in the
Linux kernel did not p
Red Hat
Kernel: KVM: OOB memory access via mmio ring buffer
vendor_redhat·2019-09-17·CVSS 8.8
CVE-2019-14821 [HIGH] CWE-787 Kernel: KVM: OOB memory access via mmio ring buffer
Kernel: KVM: OOB memory access via mmio ring buffer
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
An out-of-bounds access issue was found in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' o
Debian
CVE-2019-14821: linux - An out-of-bounds access issue was found in the Linux kernel, all versions throug...
vendor_debian·2019·CVSS 8.8
CVE-2019-14821 [HIGH] CVE-2019-14821: linux - An out-of-bounds access issue was found in the Linux kernel, all versions throug...
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
Scope: local
bookworm: resolved (fixed in 5.2.17-1)
bullseye: resolved (fixed in 5.2.17-1)
forky: resolved (fixed in 5.2.17-1)
sid: resolved (fixed in 5.2.17-1)
trixie: resolved (fixed in 5.2.17-1)
GHSA
GHSA-5xg6-r8mx-769h: An out-of-bounds access issue was found in the Linux kernel, all versions through 5
ghsa_unreviewed·2022-05-24
CVE-2019-14821 [HIGH] CWE-787 GHSA-5xg6-r8mx-769h: An out-of-bounds access issue was found in the Linux kernel, all versions through 5
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2019-10-23·CVSS 7.0
CVE-2016-10906 [HIGH] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-4163-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.
It was discovered that a race condition existed in the ARC EMAC ethernet
driver for the Linux kernel, resulting in a use-after-free vulnerability.
An attacker could use this to cause a denial of service (system crash).
(CVE-2016-10906)
It was discovered that a race condition existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel when handling certain error
conditions. A local attacker could use this to cause a denial of service
(kernel deadlock). (CVE-2017-18232)
It was discovered that the RSI 91x Wi-Fi driver i
OSV
linux-azure vulnerabilities
osv·2019-10-23·CVSS 5.5
[MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
USN-4162-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 ESM.
It was discovered that the RSI 91x Wi-Fi driver in the Linux kernel did not
did not handle detach operations correctly, leading to a use-after-free
vulnerability. A physically proximate attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-21008)
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CV
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-10-22·CVSS 7.0
CVE-2016-10906 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a race condition existed in the ARC EMAC ethernet
driver for the Linux kernel, resulting in a use-after-free vulnerability.
An attacker could use this to cause a denial of service (system crash).
(CVE-2016-10906)
It was discovered that a race condition existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel when handling certain error
conditions. A local attacker could use this to cause a denial of service
(kernel deadlock). (CVE-2017-18232)
It was discovered that the RSI 91x Wi-Fi driver in the Linux kernel did not
did not handle detach operations correctly, leading to a use-after-free
vulnerability. A physically proximate attacker could use this to cause a
denial of
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-10-22·CVSS 5.5
CVE-2018-21008 [MEDIUM] linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the RSI 91x Wi-Fi driver in the Linux kernel did not
did not handle detach operations correctly, leading to a use-after-free
vulnerability. A physically proximate attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-21008)
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco dis
OSV
linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
osv·2019-10-22·CVSS 7.8
[HIGH] linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
USN-4157-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu
18.04 LTS.
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform bounds checking when handling coalesced
MMIO write operations. A local attacker with write access to /dev/kvm co
OSV
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all versions through 5
osv·2019-09-19·CVSS 8.8
CVE-2019-14821 [HIGH] CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all versions through 5
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
Kernel
Merge tag 'for-linus-urgent' of git://git.kernel.org/pub/scm/virt/kvm/kvm
kernel_security·2019-09-18·CVSS 8.8
CVE-2019-14821 [HIGH] Merge tag 'for-linus-urgent' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Merge tag 'for-linus-urgent' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Pull KVM fix from Paolo Bonzini:
"Fix missing bounds-checking in coalesced_mmio (CVE-2019-14821)"
* tag 'for-linus-urgent' of git://git.kernel.org/pub/scm/virt/kvm/kvm:
KVM: coalesced_mmio: add bounds checking
Kernel
KVM: coalesced_mmio: add bounds checking
kernel_security·2019-09-16·CVSS 8.8
CVE-2019-14821 [HIGH] KVM: coalesced_mmio: add bounds checking
KVM: coalesced_mmio: add bounds checking
The first/last indexes are typically shared with a user app.
The app can change the 'last' index that the kernel uses
to store the next result. This change sanity checks the index
before using it for writing to a potentially arbitrary address.
This fixes CVE-2019-14821.
Cc: [email protected]
Fixes: 5f94c1741bdc ("KVM: Add coalesced MMIO support (common part)")
Signed-off-by: Matt Delco
Signed-off-by: Jim Mattson
Reported-by: [email protected]
[Use READ_ONCE. - Paolo]
Signed-off-by: Paolo Bonzini
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14821 kernel: KVM: OOB memory access via mmio ring buffer [fedora-all]
bugzilla·2019-09-19·CVSS 8.8
CVE-2019-14821 [HIGH] CVE-2019-14821 kernel: KVM: OOB memory access via mmio ring buffer [fedora-all]
CVE-2019-14821 kernel: KVM: OOB memory access via mmio ring buffer [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2019-14821 Kernel: KVM: OOB memory access via mmio ring buffer
bugzilla·2019-08-29·CVSS 8.8
CVE-2019-14821 [HIGH] CVE-2019-14821 Kernel: KVM: OOB memory access via mmio ring buffer
CVE-2019-14821 Kernel: KVM: OOB memory access via mmio ring buffer
An out-of-bounds access issue was found in the way Linux kernel's KVM hypervisor
implements Coalesced MMIO write operation. It operates on a MMIO ring buffer
'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and
'ring->last' value could be supplied by a host user-space process.
An unprivileged host user/process with access to '/dev/kvm' device could use this flaw
to crash the host kernel resulting in DoS OR potentially escalate privileges on the
system.
Upstream patch:
-> https://git.kernel.org/pub/scm/virt/kvm/kvm.git/commit/?id=b60fe990c6b07ef6d4df67bc0530c7c90a62623a
Reference:
-> https://www.openwall.com/lists/oss-security/2019/09/20/1
Discussion:
Acknowledgments:
Name: Matt Delco (Google.co
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttp://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttp://www.openwall.com/lists/oss-security/2019/09/20/1https://access.redhat.com/errata/RHSA-2019:3309https://access.redhat.com/errata/RHSA-2019:3517https://access.redhat.com/errata/RHSA-2019:3978https://access.redhat.com/errata/RHSA-2019:3979https://access.redhat.com/errata/RHSA-2019:4154https://access.redhat.com/errata/RHSA-2019:4256https://access.redhat.com/errata/RHSA-2020:0027https://access.redhat.com/errata/RHSA-2020:0204https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14821https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2019/10/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRZQQQANZWQMPILZV7OTS3RGGRLLE2Q7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3QNMPENPFEGVTOFPSNOBL7JEIJS25P/https://seclists.org/bugtraq/2019/Nov/11https://seclists.org/bugtraq/2019/Sep/41https://security.netapp.com/advisory/ntap-20191004-0001/https://usn.ubuntu.com/4157-1/https://usn.ubuntu.com/4157-2/https://usn.ubuntu.com/4162-1/https://usn.ubuntu.com/4162-2/https://usn.ubuntu.com/4163-1/https://usn.ubuntu.com/4163-2/https://www.debian.org/security/2019/dsa-4531https://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttp://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttp://www.openwall.com/lists/oss-security/2019/09/20/1https://access.redhat.com/errata/RHSA-2019:3309https://access.redhat.com/errata/RHSA-2019:3517https://access.redhat.com/errata/RHSA-2019:3978https://access.redhat.com/errata/RHSA-2019:3979https://access.redhat.com/errata/RHSA-2019:4154https://access.redhat.com/errata/RHSA-2019:4256https://access.redhat.com/errata/RHSA-2020:0027https://access.redhat.com/errata/RHSA-2020:0204https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14821https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2019/10/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRZQQQANZWQMPILZV7OTS3RGGRLLE2Q7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3QNMPENPFEGVTOFPSNOBL7JEIJS25P/https://seclists.org/bugtraq/2019/Nov/11https://seclists.org/bugtraq/2019/Sep/41https://security.netapp.com/advisory/ntap-20191004-0001/https://usn.ubuntu.com/4157-1/https://usn.ubuntu.com/4157-2/https://usn.ubuntu.com/4162-1/https://usn.ubuntu.com/4162-2/https://usn.ubuntu.com/4163-1/https://usn.ubuntu.com/4163-2/https://www.debian.org/security/2019/dsa-4531https://www.oracle.com/security-alerts/cpuapr2020.html
2019-09-19
Published