HIGH · 8.8

CVE-2019-14821

An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ri...

Vulnerability Description

An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel>= 2.6.27, <= 3.15.10
RedhatVirtualization Host4.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus7.7
RedhatEnterprise Linux For Real Time7
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus7.7
RedhatEnterprise Linux Server Tus7.7
RedhatEnterprise Linux Workstation6.0
CanonicalUbuntu Linux14.04
OpensuseLeap15.0
FedoraprojectFedora29
DebianDebian Linux8.0
NetappAff A700S Firmware-
NetappAff A700S-
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-14821?

CVE-2019-14821 is a vulnerability with a CVSS score of 8.8 (HIGH). An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ri...

How severe is CVE-2019-14821?

CVE-2019-14821 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-14821?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Virtualization Host, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus.