CVE-2019-14835

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.09 % (41th)
0.09% Progress
Affected Products 45
Advisories 42

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.

Weaknesses
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2019-09-17 16:15:10
(5 years ago)
Updated Date
2023-12-15 15:29:09
(9 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.34 version and prior 3.16.74 version cpe:2.3:o:linux:linux_kernel >= 2.6.34 < 3.16.74
  Linux Kernel from 4.4 version and prior 4.4.193 version cpe:2.3:o:linux:linux_kernel >= 4.4 < 4.4.193
  Linux Kernel from 4.9 version and prior 4.9.193 version cpe:2.3:o:linux:linux_kernel >= 4.9 < 4.9.193
  Linux Kernel from 4.14 version and prior 4.14.144 version cpe:2.3:o:linux:linux_kernel >= 4.14 < 4.14.144
  Linux Kernel from 4.19 version and prior 4.19.73 version cpe:2.3:o:linux:linux_kernel >= 4.19 < 4.19.73
  Linux Kernel from 5.2 version and prior 5.2.15 version cpe:2.3:o:linux:linux_kernel >= 5.2 < 5.2.15
  Linux Kernel 5.3 cpe:2.3:o:linux:linux_kernel:5.3

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts
  Canonical Ubuntu Linux 19.04 cpe:2.3:o:canonical:ubuntu_linux:19.04

Configuration #3

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #4

    CPE23 From Up To
  Fedoraproject Fedora 29 cpe:2.3:o:fedoraproject:fedora:29
  Fedoraproject Fedora 30 cpe:2.3:o:fedoraproject:fedora:30

Configuration #5

    CPE23 From Up To
  Opensuse Leap 15.0 cpe:2.3:o:opensuse:leap:15.0
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp Aff A700s Firmware cpe:2.3:o:netapp:aff_a700s_firmware:-
OR  
  Running on/with
  Netapp Aff A700s cpe:2.3:h:netapp:aff_a700s

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp H410c Firmware cpe:2.3:o:netapp:h410c_firmware:-
OR  
  Running on/with
  Netapp H410c cpe:2.3:h:netapp:h410c

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp H610s Firmware cpe:2.3:o:netapp:h610s_firmware:-
OR  
  Running on/with
  Netapp H610s cpe:2.3:h:netapp:h610s

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H300s Firmware cpe:2.3:o:netapp:h300s_firmware:-
OR  
  Running on/with
  Netapp H300s cpe:2.3:h:netapp:h300s

Configuration #10

AND
    CPE23 From Up To
OR  
  Netapp H500s Firmware cpe:2.3:o:netapp:h500s_firmware:-
OR  
  Running on/with
  Netapp H500s cpe:2.3:h:netapp:h500s

Configuration #11

AND
    CPE23 From Up To
OR  
  Netapp H700s Firmware cpe:2.3:o:netapp:h700s_firmware:-
OR  
  Running on/with
  Netapp H700s cpe:2.3:h:netapp:h700s

Configuration #12

AND
    CPE23 From Up To
OR  
  Netapp H300e Firmware cpe:2.3:o:netapp:h300e_firmware:-
OR  
  Running on/with
  Netapp H300e cpe:2.3:h:netapp:h300e

Configuration #13

AND
    CPE23 From Up To
OR  
  Netapp H500e Firmware cpe:2.3:o:netapp:h500e_firmware:-
OR  
  Running on/with
  Netapp H500e cpe:2.3:h:netapp:h500e

Configuration #14

AND
    CPE23 From Up To
OR  
  Netapp H700e Firmware cpe:2.3:o:netapp:h700e_firmware:-
OR  
  Running on/with
  Netapp H700e cpe:2.3:h:netapp:h700e

Configuration #15

AND
    CPE23 From Up To
OR  
  Netapp H410s Firmware cpe:2.3:o:netapp:h410s_firmware:-
OR  
  Running on/with
  Netapp H410s cpe:2.3:h:netapp:h410s

Configuration #16

    CPE23 From Up To
  Netapp Data Availability Services cpe:2.3:a:netapp:data_availability_services:-
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
  Netapp Service Processor cpe:2.3:a:netapp:service_processor:-
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-
  Netapp Steelstore Cloud Integrated Storage cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-

Configuration #17

    CPE23 From Up To
  Redhat Openshift Container Platform 3.11 cpe:2.3:a:redhat:openshift_container_platform:3.11
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
  Redhat Enterprise Linux Desktop 6.0 cpe:2.3:o:redhat:enterprise_linux_desktop:6.0
  Redhat Enterprise Linux Desktop 7.0 cpe:2.3:o:redhat:enterprise_linux_desktop:7.0
  Redhat Enterprise Linux Eus 7.5 cpe:2.3:o:redhat:enterprise_linux_eus:7.5
  Redhat Enterprise Linux Eus 7.6 cpe:2.3:o:redhat:enterprise_linux_eus:7.6
  Redhat Enterprise Linux Eus 7.7 cpe:2.3:o:redhat:enterprise_linux_eus:7.7
  Redhat Enterprise Linux for Real Time 7 cpe:2.3:o:redhat:enterprise_linux_for_real_time:7
  Redhat Enterprise Linux for Real Time 8 cpe:2.3:o:redhat:enterprise_linux_for_real_time:8
  Redhat Enterprise Linux Server 6.0 cpe:2.3:o:redhat:enterprise_linux_server:6.0
  Redhat Enterprise Linux Server 7.0 cpe:2.3:o:redhat:enterprise_linux_server:7.0
  Redhat Enterprise Linux Server 7.6 cpe:2.3:o:redhat:enterprise_linux_server:7.6
  Redhat Enterprise Linux Server Aus 6.5 cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5
  Redhat Enterprise Linux Server Aus 6.6 cpe:2.3:o:redhat:enterprise_linux_server_aus:6.6
  Redhat Enterprise Linux Server Aus 7.2 cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2
  Redhat Enterprise Linux Server Aus 7.3 cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3
  Redhat Enterprise Linux Server Aus 7.4 cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4
  Redhat Enterprise Linux Server Aus 7.6 cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6
  Redhat Enterprise Linux Server Aus 7.7 cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7
  Redhat Enterprise Linux Server Tus 7.2 cpe:2.3:o:redhat:enterprise_linux_server_tus:7.2
  Redhat Enterprise Linux Server Tus 7.3 cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3
  Redhat Enterprise Linux Server Tus 7.4 cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4
  Redhat Enterprise Linux Server Tus 7.6 cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6
  Redhat Enterprise Linux Server Tus 7.7 cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7
  Redhat Enterprise Linux Workstation 6.0 cpe:2.3:o:redhat:enterprise_linux_workstation:6.0
  Redhat Enterprise Linux Workstation 7.0 cpe:2.3:o:redhat:enterprise_linux_workstation:7.0

Configuration #18

AND
    CPE23 From Up To
OR  
  Redhat Virtualization 4.0 cpe:2.3:a:redhat:virtualization:4.0
OR  
  Running on/with
  Redhat Virtualization Host 4.0 cpe:2.3:a:redhat:virtualization_host:4.0
OR  
  Running on/with
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0

Configuration #19

    CPE23 From Up To
  Huawei Imanager Neteco V600r009c00 cpe:2.3:a:huawei:imanager_neteco:v600r009c00
  Huawei Imanager Neteco V600r009c10spc200 cpe:2.3:a:huawei:imanager_neteco:v600r009c10spc200
  Huawei Imanager Neteco 6000 V600r008c10spc300 cpe:2.3:a:huawei:imanager_neteco_6000:v600r008c10spc300
  Huawei Imanager Neteco 6000 V600r008c20 cpe:2.3:a:huawei:imanager_neteco_6000:v600r008c20
  Huawei Manageone 6.5.0 cpe:2.3:a:huawei:manageone:6.5.0
  Huawei Manageone 6.5.0.spc100.b210 cpe:2.3:a:huawei:manageone:6.5.0.spc100.b210
  Huawei Manageone 6.5.1rc1.b060 cpe:2.3:a:huawei:manageone:6.5.1rc1.b060
  Huawei Manageone 6.5.1rc1.b080 cpe:2.3:a:huawei:manageone:6.5.1rc1.b080
  Huawei Manageone 6.5.rc2.b050 cpe:2.3:a:huawei:manageone:6.5.rc2.b050
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...