ZeroHour

CVE-2019-14835

PoC
CVSS 3.1
7.8 high
EPSS
<1%p48
Published
()
Modified
Description

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.

Vendors
linuxcanonicaldebianfedoraprojectopensusenetappredhathuawei
Products
linux kernel, ubuntu linux, debian linux, fedora, leap, aff a700s firmware, h410c firmware, h610s firmware, h300s firmware, h500s firmware, h700s firmware, h300e firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.