CVE-2019-3016Sensitive Information Exposure in Linux

Severity
4.7MEDIUMNVD
OSV7.5OSV6.2OSV4.6
EPSS
0.1%
top 80.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateMay 24

Description

In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages29 packages

Debianlinux/linux_kernel< 5.4.19-1+3
Ubuntulinux/linux_kernel< 4.4.0-177.207+1
CVEListV5linux/linux_kernel4.10 to 5.6

Patches

🔴Vulnerability Details

11
GHSA
GHSA-g7mw-cr59-r458: In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same gues2022-05-24
OSV
Kernel Live Patch Security Notice2020-04-09
OSV
linux-aws-5.0, linux-gcp, linux-gke-5.0, linux-oracle-5.0, linux-azure vulnerabilities2020-03-25
OSV
linux, linux-aws, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-raspi2-5.3, linux-azure, linux-azure-5.3 vulnerabilities2020-03-25
OSV
CVE-2019-3016: In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same gues2020-01-31

📋Vendor Advisories

6
Ubuntu
Kernel Live Patch Security Notice2020-04-09
Ubuntu
Linux kernel vulnerabilities2020-03-25
Ubuntu
Linux kernel vulnerabilities2020-03-25
Red Hat
kernel: kvm: Information leak within a KVM guest2020-01-30
Microsoft
In a Linux KVM guest that has PV TLB enabled a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux 2020-01-14

💬Community

2
Bugzilla
CVE-2019-3016 kernel: kvm: Information leak within a KVM guest [fedora-all]2020-01-30
Bugzilla
CVE-2019-3016 kernel: kvm: Information leak within a KVM guest2020-01-17