PT-2019-5698 · Linux+6 · Linux Kernel+6

Prasad J Pandit

·

Published

2019-12-03

·

Updated

2024-06-15

·

CVE-2019-19332

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions 3.13 through 5.4
Description An out-of-bounds memory write issue was found in the Linux Kernel's KVM hypervisor, related to the handling of the 'KVM GET EMULATED CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the '/dev/kvm' device could use this flaw to crash the system, resulting in a denial of service. The issue may also allow an attacker to compromise data integrity.
Recommendations For Linux Kernel versions 3.13 through 5.4, consider restricting access to the '/dev/kvm' device to minimize the risk of exploitation. As a temporary workaround, limiting the use of the KVM hypervisor's 'KVM GET EMULATED CPUID' ioctl(2) request may help mitigate the issue until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4431
ALSA-2020_4431
ALT-PU-2019-3291
ALT-PU-2019-3292
ALT-PU-2019-3293
ALT-PU-2019-3326
ALT-PU-2019-3343
ALT-PU-2019-3369
ALT-PU-2020-1025
ALT-PU-2020-1028
ALT-PU-2020-1070
ALT-PU-2020-1198
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-1501
ALT-PU-2020-1714
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1745
ALT-PU-2021-1870
BDU:2020-05893
CESA-2020_4060
CESA-2020_4431
CESA-2020_4609
CVE-2019-19332
DLA-2068-1
DLA-2114-1
ELSA-2020-4060
ELSA-2020-4431
ELSA-2020-5528
ELSA-2020-5533
ELSA-2020-5535
MGASA-2019-0388
MGASA-2020-0089
OPENSUSE-SU-2020:0336-1
OPENSUSE-SU-2020_0336-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2020:4060
RHSA-2020:4062
RHSA-2020:4431
RHSA-2020:4609
RHSA-2020_4060
RHSA-2020_4062
RHSA-2020_4431
RHSA-2020_4609
SUSE-SU-2019:3316-1
SUSE-SU-2019:3379-1
SUSE-SU-2019:3381-1
SUSE-SU-2019:3389-1
SUSE-SU-2019_3389-1
SUSE-SU-2020:0093-1
SUSE-SU-2020:0511-1
SUSE-SU-2020:0560-1
SUSE-SU-2020:0584-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1255-1
SUSE-SU-2020_0511-1
SUSE-SU-2020_0560-1
SUSE-SU-2020_0584-1
USN-4254-1
USN-4254-2
USN-4258-1
USN-4284-1
USN-4287-1
USN-4287-2

Affected Products

Alt Linux
Almalinux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu