CVE-2019-14835
Last modified
CVE-2019-14835 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.34, < 3.16.74 |
| Linux | Linux Kernel | >= 4.4, < 4.4.193 |
| Linux | Linux Kernel | >= 4.9, < 4.9.193 |
| Linux | Linux Kernel | >= 4.14, < 4.14.144 |
| Linux | Linux Kernel | >= 4.19, < 4.19.73 |
| Linux | Linux Kernel | >= 5.2, < 5.2.15 |
| Linux | Linux Kernel | 5.3 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.04 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Fedoraproject | Fedora | 29 |
| Fedoraproject | Fedora | 30 |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 15.1 |
| Netapp | Aff A700s Firmware | All versions |
| Netapp | H410c Firmware | All versions |
| Netapp | H610s Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H300e Firmware | All versions |
| Netapp | H500e Firmware | All versions |
| Netapp | H700e Firmware | All versions |
| Netapp | H410s Firmware | All versions |
| Netapp | Data Availability Services | All versions |
| Netapp | Hci Management Node | All versions |
| Netapp | Service Processor | All versions |
| Netapp | Solidfire | All versions |
| Netapp | Steelstore Cloud Integrated Storage | All versions |
| Redhat | Openshift Container Platform | 3.11 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Eus | 7.5 |
| Redhat | Enterprise Linux Eus | 7.6 |
| Redhat | Enterprise Linux Eus | 7.7 |
| Redhat | Enterprise Linux For Real Time | 7 |
| Redhat | Enterprise Linux For Real Time | 8 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server | 7.6 |
| Redhat | Enterprise Linux Server Aus | 6.5 |
| Redhat | Enterprise Linux Server Aus | 6.6 |
| Redhat | Enterprise Linux Server Aus | 7.2 |
| Redhat | Enterprise Linux Server Aus | 7.3 |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.htmlMailing List, Third Party Advisory
- https://packetstormsecurity.com/files/154572/Kernel-Live-Patch-Security-Notice-LSN-0056-1.htmlThird Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlThird Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlThird Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2019/10/03/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/10/09/3Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/10/09/7Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHBA-2019:2824Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2827Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2828Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2829Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2830Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2854Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2862Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2863Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2864Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2865Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2866Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2867Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2869Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2889Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2899Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2900Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2901Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2924Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14835Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00000.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Nov/11Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/41Issue Tracking, Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20191031-0005/Third Party Advisory
- https://usn.ubuntu.com/4135-1/Third Party Advisory
- https://usn.ubuntu.com/4135-2/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4531Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/09/17/1Exploit, Mailing List, Patch, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.htmlMailing List, Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.htmlMailing List, Third Party Advisory
- https://packetstormsecurity.com/files/154572/Kernel-Live-Patch-Security-Notice-LSN-0056-1.htmlThird Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlThird Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlThird Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2019/10/03/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/10/09/3Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/10/09/7Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHBA-2019:2824Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2827Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2828Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2829Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2830Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2854Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2862Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2863Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2864Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2865Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2866Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2867Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2869Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2889Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2899Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2900Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2901Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2924Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14835Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00000.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Nov/11Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/41Issue Tracking, Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20191031-0005/Third Party Advisory
- https://usn.ubuntu.com/4135-1/Third Party Advisory
- https://usn.ubuntu.com/4135-2/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4531Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/09/17/1Exploit, Mailing List, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14835?
How severe is CVE-2019-14835?
How do I fix CVE-2019-14835?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1483An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2019-14830A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6…6.1
- CVE-2019-14831A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6…6.1
- CVE-2019-14832A flaw was found in the Keycloak REST API before version 8.0…7.5
- CVE-2019-14833A flaw was found in Samba, all versions starting samba 4.5.0…5.4
- CVE-2019-14834A vulnerability was found in dnsmasq before version 2.81, wh…3.7
- CVE-2019-14836A vulnerability was found that the 3scale dev portal does no…8.8
- CVE-2019-14837A flaw was found in keycloack before version 8.0.0. The owne…9.1
- CVE-2019-14838A flaw was found in wildfly-core before 7.2.5.GA. The Manage…4.9
- CVE-2019-14839It was observed that while login into Business-central conso…7.5
- CVE-2019-1484A remote code execution vulnerability exists when Microsoft …7.8
- CVE-2019-14840A flaw was found in the RHDM, where sensitive HTML form fiel…7.5
Are you affected by CVE-2019-14835?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
