CVE-2019-14821Out-of-bounds Write in Kernel

CWE-787Out-of-bounds Write17 documents10 sources
Severity
8.8HIGHNVD
EPSS
0.1%
top 71.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateMay 24

Description

An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of servic

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages9 packages

NVDlinux/linux_kernel3.163.16.74+8
Debianlinux/linux_kernel< 5.2.17-1+3
CVEListV5linux/kernelall through 5.3

Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 19.04, Enterprise Linux 8.0, 7.7, 7, 8, Fedora 29, 30

Patches

🔴Vulnerability Details

5
GHSA
GHSA-5xg6-r8mx-769h: An out-of-bounds access issue was found in the Linux kernel, all versions through 52022-05-24
OSV
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all versions through 52019-09-19
CVEList
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all versions through 52019-09-19
Kernel
Merge tag 'for-linus-urgent' of git://git.kernel.org/pub/scm/virt/kvm/kvm2019-09-18
Kernel
KVM: coalesced_mmio: add bounds checking2019-09-16

📋Vendor Advisories

9
Oracle
Oracle Oracle Communications Applications Risk Matrix: OS (Kernel) — CVE-2019-148212020-04-15
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2019-10-23
Ubuntu
Linux kernel (Azure) vulnerabilities2019-10-23
Ubuntu
Linux kernel vulnerabilities2019-10-22
Ubuntu
Linux kernel (HWE) vulnerabilities2019-10-22

💬Community

2
Bugzilla
CVE-2019-14821 kernel: KVM: OOB memory access via mmio ring buffer [fedora-all]2019-09-19
Bugzilla
CVE-2019-14821 Kernel: KVM: OOB memory access via mmio ring buffer2019-08-29
CVE-2019-14821 — Out-of-bounds Write in Linux Kernel | cvebase