cbcvebase.
CVE-2019-6974
published 2019-02-15

CVE-2019-6974: In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EXPLOIT
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.19.20-1 (bookworm)linux 4.19.20-1 (bookworm)
f5big-ip_access_policy_manager13.0.0 – 13.1.1
f5big-ip_access_policy_manager14.0.0 – 14.1.0
f5big-ip_access_policy_manager>= 15.0.0 < 15.1.015.1.0
f5big-ip_advanced_firewall_manager13.0.0 – 13.1.1
f5big-ip_advanced_firewall_manager14.0.0 – 14.1.0
f5big-ip_advanced_firewall_manager>= 15.0.0 < 15.1.015.1.0
f5big-ip_analytics13.0.0 – 13.1.1
f5big-ip_analytics14.0.0 – 14.1.0
f5big-ip_analytics>= 15.0.0 < 15.1.015.1.0
f5big-ip_application_acceleration_manager13.0.0 – 13.1.1
f5big-ip_application_acceleration_manager14.0.0 – 14.1.0
f5big-ip_application_acceleration_manager>= 15.0.0 < 15.1.015.1.0
f5big-ip_application_security_manager13.0.0 – 13.1.1
f5big-ip_application_security_manager14.0.0 – 14.1.0
f5big-ip_application_security_manager>= 15.0.0 < 15.1.015.1.0
f5big-ip_edge_gateway13.0.0 – 13.1.1
f5big-ip_edge_gateway14.0.0 – 14.1.0
f5big-ip_edge_gateway>= 15.0.0 < 15.1.015.1.0

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH