CVE-2019-7221

CWE-416Use After Free17 documents9 sources
Severity
7.8HIGH
EPSS
0.1%
top 82.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

Also affects: Debian Linux 8.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 7.0, 7.6, Fedora 28, 29, Openshift Container Platform 3.11

Patches

🔴Vulnerability Details

6
GHSA
GHSA-jc59-87wq-g5xp: The KVM implementation in the Linux kernel through 42022-05-13
OSV
CVE-2019-7221: The KVM implementation in the Linux kernel through 42019-03-21
CVEList
CVE-2019-7221: The KVM implementation in the Linux kernel through 42019-03-17
Kernel
Merge tag 'v5.0-rc6' into for-5.1/block2019-02-15
Kernel
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm2019-02-07

📋Vendor Advisories

8
Ubuntu
Linux kernel (HWE) vulnerabilities2019-04-02
Ubuntu
Linux kernel (HWE) vulnerabilities2019-04-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2019-04-02

💬Community

2
Bugzilla
CVE-2019-7221 kernel: KVM: nVMX: use-after-free of the hrtimer for emulation of the preemption timer [fedora-all]2019-02-07
Bugzilla
CVE-2019-7221 Kernel: KVM: nVMX: use-after-free of the hrtimer for emulation of the preemption timer2019-02-02
CVE-2019-7221 (HIGH CVSS 7.8) | The KVM implementation in the Linux | cvebase.io