PT-2019-5698 · Linux+6 · Linux Kernel+6
Prasad J Pandit
·
Published
2019-12-03
·
Updated
2024-06-15
·
CVE-2019-19332
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Linux Kernel versions 3.13 through 5.4
Description
An out-of-bounds memory write issue was found in the Linux Kernel's KVM hypervisor, related to the handling of the 'KVM GET EMULATED CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the '/dev/kvm' device could use this flaw to crash the system, resulting in a denial of service. The issue may also allow an attacker to compromise data integrity.
Recommendations
For Linux Kernel versions 3.13 through 5.4, consider restricting access to the '/dev/kvm' device to minimize the risk of exploitation. As a temporary workaround, limiting the use of the KVM hypervisor's 'KVM GET EMULATED CPUID' ioctl(2) request may help mitigate the issue until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu