CVE-2019-14835

Severity
7.8HIGH
EPSS
0.1%
top 78.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17
Latest updateMay 24

Description

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages26 packages

NVDlinux/linux_kernel2.6.343.16.74+6
CVEListV5linux_kernel/linux_kernelfrom version 2.6.34 to 5.2.x
Debianlinux< 5.2.17-1+3
Ubuntulinux< 4.4.0-164.192+2

Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 19.04, Enterprise Linux 8.0, 7.5, 7.6, 7.7, 7, 8, 6.5, 6.6, 7.2, 7.3, 7.4, Fedora 29, 30, Openshift Container Platform 3.11

Patches

🔴Vulnerability Details

6
GHSA
GHSA-h3vw-f6h8-86mg: A buffer overflow flaw was found, in versions from 22022-05-24
Kernel
fortify: Detect struct member overflows in memcpy() at compile-time2021-04-20
OSV
linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities2019-09-18
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-gke-5.0, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2019-09-18
CVEList
CVE-2019-14835: A buffer overflow flaw was found, in versions from 22019-09-17

📋Vendor Advisories

3
Ubuntu
Linux kernel vulnerabilities2019-09-18
Red Hat
kernel: vhost-net: guest to host kernel escape during migration2019-09-17
Debian
CVE-2019-14835: linux - A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way L...2019

💬Community

2
Bugzilla
CVE-2019-14835 kernel: vhost-net: guest to host kernel escape during migration [fedora-all]2019-09-17
Bugzilla
CVE-2019-14835 kernel: vhost-net: guest to host kernel escape during migration2019-09-10
CVE-2019-14835 (HIGH CVSS 7.8) | A buffer overflow flaw was found | cvebase.io