CVE-2019-7222Sensitive Information Exposure in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 87.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 18.10, Enterprise Linux 8.0, 8.1, 8.2, 8.4, 8.6, 7, 8, Fedora 28, 29

Patches

🔴Vulnerability Details

6
GHSA
GHSA-57xj-x7jh-222m: The KVM implementation in the Linux kernel through 42022-05-13
OSV
CVE-2019-7222: The KVM implementation in the Linux kernel through 42019-03-21
CVEList
CVE-2019-7222: The KVM implementation in the Linux kernel through 42019-03-17
Kernel
Merge tag 'v5.0-rc6' into for-5.1/block2019-02-15
Kernel
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm2019-02-07

📋Vendor Advisories

10
Ubuntu
Linux kernel (HWE) vulnerabilities2019-04-02
Ubuntu
Linux kernel (HWE) vulnerabilities2019-04-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2019-04-02

💬Community

2
Bugzilla
CVE-2019-7222 kernel: KVM: leak of uninitialized stack contents to guest [fedora-all]2019-02-07
Bugzilla
CVE-2019-7222 Kernel: KVM: leak of uninitialized stack contents to guest2019-02-02