cbcvebase.
CVE-2019-3016
published 2020-01-31

CVE-2019-3016: In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This…

PriorityP421medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.62%
46.2th percentile
In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.4.19-1 (bookworm)linux 5.4.19-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.4.19-15.4.19-1
linuxlinux_kernel>= 0 < 5.4.19-15.4.19-1
linuxlinux_kernel>= 0 < 5.4.19-15.4.19-1
linuxlinux_kernel>= 0 < 5.4.19-15.4.19-1
linuxlinux_kernel>= 0 < 4.4.0-177.2074.4.0-177.207
linuxlinux_kernel>= 0 < 4.15.0-96.974.15.0-96.97
linuxlinux_kernel>= 4.16
msrcazl3_kernel_6.6.29.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrcbpftool-5.15.32.1-3.cm2.aarch64.rpm
msrcbpftool-5.15.32.1-3.cm2.x86_64.rpm
msrcbpftool-6.6.29.1-4.azl3.aarch64.rpm
msrcbpftool-6.6.29.1-4.azl3.x86_64.rpm
msrccbl2_kernel_5.10.78.1-1_on_cbl_mariner_2.0
msrccm1_kernel_5.10.60.1-1_on_cbl_mariner_1.0
msrckernel-5.10.60.1-1.cm1.aarch64.rpm
msrckernel-5.10.60.1-1.cm1.x86_64.rpm
msrckernel-5.15.32.1-3.cm2.aarch64.rpm
msrckernel-5.15.32.1-3.cm2.x86_64.rpm
msrckernel-6.6.29.1-4.azl3.aarch64.rpm
msrckernel-6.6.29.1-4.azl3.x86_64.rpm
msrckernel-debuginfo-5.10.60.1-1.cm1.aarch64.rpm

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.