HIGH · 7.8

CVE-2019-14835

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migrat...

Vulnerability Description

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel>= 2.6.34, < 3.16.74
CanonicalUbuntu Linux12.04
DebianDebian Linux8.0
FedoraprojectFedora29
OpensuseLeap15.0
NetappAff A700S Firmware-
NetappAff A700SAll versions
NetappH410C Firmware-
NetappH410CAll versions
NetappH610S Firmware-
NetappH610SAll versions
NetappH300S Firmware-
NetappH300SAll versions
NetappH500S Firmware-
NetappH500SAll versions
NetappH700S Firmware-
NetappH700SAll versions
NetappH300E Firmware-
NetappH300EAll versions
NetappH500E Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-14835?

CVE-2019-14835 is a vulnerability with a CVSS score of 7.8 (HIGH). A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migrat...

How severe is CVE-2019-14835?

CVE-2019-14835 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-14835?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Canonical Ubuntu Linux, Debian Debian Linux, Fedoraproject Fedora, Opensuse Leap.