cbcvebase.
CVE-2019-19332
published 2020-01-09

CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the…

PriorityP427medium6.1CVSS 3.1
AVLACLPRLUINSUCNILAH
EPSS
0.68%
48.6th percentile
An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the '/dev/kvm' device could use this flaw to crash the system, resulting in a denial of service.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.4.6-1 (bookworm)linux 5.4.6-1 (bookworm)
linuxkernel
linuxlinux_kernel>= 0 < 5.4.6-15.4.6-1
linuxlinux_kernel>= 0 < 5.4.6-15.4.6-1
linuxlinux_kernel>= 0 < 5.4.6-15.4.6-1
linuxlinux_kernel>= 0 < 5.4.6-15.4.6-1
linuxlinux_kernel>= 0 < 4.4.0-173.2034.4.0-173.203
linuxlinux_kernel>= 0 < 4.15.0-88.884.15.0-88.88
linuxlinux_kernel3.13 – 5.4
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
nvdv3.06.1MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
nvdv2.05.6MEDIUMAV:L/AC:L/Au:N/C:N/I:P/A:C
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.