CVE-2019-19332

CWE-787Out-of-bounds Write16 documents9 sources
Severity
6.1MEDIUM
EPSS
0.0%
top 93.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateMay 24

Description

An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the '/dev/kvm' device could use this flaw to crash the system, resulting in a denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:HExploitability: 1.8 | Impact: 4.2

Affected Packages3 packages

NVDlinux/linux_kernel3.135.4
CVEListV5linux/kernel3.13 through 5.4
Debianlinux< 5.4.6-1+3

Also affects: Enterprise Linux 7.0, 8.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-v6jm-gf32-wr3v: An out-of-bounds memory write issue was found in the Linux Kernel, version 32022-05-24
OSV
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel, version 32020-01-09
CVEList
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel, version 32020-01-09
Kernel
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm2019-12-04
Kernel
KVM: x86: fix out-of-bounds write in KVM_GET_EMULATED_CPUID (CVE-2019-19332)2019-12-04

📋Vendor Advisories

8
Ubuntu
Linux kernel vulnerabilities2020-02-19
Ubuntu
Linux kernel vulnerabilities2020-02-18
Ubuntu
Linux kernel (Azure) vulnerabilities2020-02-18
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2020-01-29
Ubuntu
Linux kernel vulnerabilities2020-01-29

💬Community

2
Bugzilla
CVE-2019-19332 kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid [fedora-all]2019-12-13
Bugzilla
CVE-2019-19332 Kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid2019-12-04
CVE-2019-19332 (MEDIUM CVSS 6.1) | An out-of-bounds memory write issue | cvebase.io