CVE-2019-14835: Buffer Overflow
A buffer overflow flaw was found in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
Other sources
A buffer overflow flaw was found in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. In the worst case (and likely most common virtualization) scenario this flaw affects KVM/qemu hypervisor enabled hosts running Linux guests.
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
Affected Software
Remediation
Information
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-14835?
CVE-2019-14835 is a buffer overflow vulnerability found in the Linux kernel's vhost functionality.
How does CVE-2019-14835 affect Linux?
CVE-2019-14835 allows privileged guest users to exploit a buffer overflow flaw in the vhost functionality of the Linux kernel.
What is the severity of CVE-2019-14835?
CVE-2019-14835 has a severity level of high.
How can I fix CVE-2019-14835?
To fix CVE-2019-14835, it is recommended to update your Linux kernel to a version that includes the patch for the vulnerability.
Where can I find more information about CVE-2019-14835?
You can find more information about CVE-2019-14835 on the official Red Hat Security Advisory and the Git repository for the Linux kernel.