CVE-2019-14821
linux - security update
8.8
HIGH
CVSS 3.1
EPSS 0.11%
Description
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
How to fix CVE-2019-14821
To remediate CVE-2019-14821, upgrade the affected package to a fixed version below.
- —upgrade to 5.2.17-1 or later
- —upgrade to 4.9.189-3+deb9u1 or later
- —upgrade to 4.9.189-3+deb9u1~deb8u1 or later
Is CVE-2019-14821 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 5.2.17-1
- from 0, < 4.9.189-3+deb9u1
- from 0, < 4.9.189-3+deb9u1~deb8u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |