PT-2019-4108 · Linux+5 · Linux Kernel+5

Published

2014-10-23

·

Updated

2024-02-16

·

CVE-2019-14821

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.3
Description The issue is related to an out-of-bounds access problem in the Linux kernel's KVM hypervisor, specifically in the Coalesced MMIO write operation. This operation uses an MMIO ring buffer 'struct kvm coalesced mmio' object, where write indices 'ring->first' and 'ring->last' can be supplied by a host user-space process. An unprivileged host user or process with access to the '/dev/kvm' device could exploit this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
Recommendations For Linux kernel versions through 5.3, consider restricting access to the '/dev/kvm' device to minimize the risk of exploitation. As a temporary workaround, limiting the use of the Coalesced MMIO write operation until a patch is available may help mitigate the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2297
ALT-PU-2015-1794
ALT-PU-2016-1262
ALT-PU-2017-1299
ALT-PU-2018-1557
ALT-PU-2019-1139
ALT-PU-2019-1363
ALT-PU-2019-2762
ALT-PU-2019-2763
ALT-PU-2019-2764
ALT-PU-2019-2768
ALT-PU-2019-2838
ALT-PU-2019-2845
ALT-PU-2019-2890
ALT-PU-2019-2891
ALT-PU-2020-1024
ALT-PU-2020-1025
ALT-PU-2020-1070
ALT-PU-2020-1714
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1745
BDU:2019-04677
CESA-2019_3309
CESA-2019_3517
CESA-2019_3979
CESA-2019_4256
CVE-2019-14821
DLA-1930-1
DLA-1940-1
DSA-4531-1
MGASA-2019-0287
MGASA-2019-0288
MGASA-2019-0333
OPENSUSE-SU-2019:2307-1
OPENSUSE-SU-2019:2308-1
OPENSUSE-SU-2019_2307-1
OPENSUSE-SU-2019_2308-1
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019:3978
RHSA-2019:3979
RHSA-2019:4154
RHSA-2019:4256
RHSA-2019_3309
RHSA-2019_3517
RHSA-2019_3978
RHSA-2019_3979
RHSA-2019_4256
RHSA-2020:0027
RHSA-2020:0204
RHSA-2020:2851
SUSE-SU-2019:14218-1
SUSE-SU-2019:2648-1
SUSE-SU-2019:2651-1
SUSE-SU-2019:2658-1
SUSE-SU-2019:2706-1
SUSE-SU-2019:2710-1
SUSE-SU-2019:2756-1
SUSE-SU-2019:2879-1
SUSE-SU-2019:2949-1
SUSE-SU-2019:2950-1
SUSE-SU-2019:2984-1
SUSE-SU-2019:3200-1
SUSE-SU-2019:3295-1
SUSE-SU-2019_14218-1
SUSE-SU-2020:0093-1
USN-4157-1
USN-4157-2
USN-4162-1
USN-4162-2
USN-4163-1
USN-4163-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu