CVE-2019-3016: Race Condition

Published Jan 17, 2020
·
Updated

A flaw was found in the way Linux kernel's KVM hypervisor handled deferred TLB flush requests from guest. A race condition may occur between guest issuing a deferred TLB flush request to KVM and KVM handling and acknowledging it. This may result in invalid address translations from TLB being used to access guest memory, leading to potential information leakage issue.

A guest user/process may use this flaw to access guest memory locations which it should not have access to.

Upstream patches: ----------------- -> https://git.kernel.org/linus/a6bd811f1209fe1c64c9f6fd578101d6436c6b6e -> https://git.kernel.org/linus/b043138246a41064527cf019a3d51d9f015e9796 -> https://git.kernel.org/linus/917248144db5d7320655dbb41d3af0b8a0f3d589 -> https://git.kernel.org/linus/1eff70a9abd46f175defafd29bc17ad456f398a7 -> https://git.kernel.org/linus/8c6de56a42e0c657955e12b882a81ef07d1d073e -> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/?qt=grep&q=CVE-2019-3016

Other sources

A flaw was found in the way Linux kernel's KVM hypervisor handled deferred TLB flush requests from guest. A race condition may occur between the guest issuing a deferred TLB flush request to KVM, and then KVM handling and acknowledging it. This may result in invalid address translations from TLB being used to access guest memory, leading to a potential information leakage issue. An attacker may use this flaw to access guest memory locations that it should not have access to.

In a Linux KVM guest that has PV TLB enabled a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.

Microsoft

In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.

Affected Software

62 affected componentsFixes available
redhat/kernel-rt<0:4.18.0-193.13.2.rt13.65.el8_2
0:4.18.0-193.13.2.rt13.65.el8_2
redhat/kernel<0:4.18.0-193.13.2.el8_2
0:4.18.0-193.13.2.el8_2
Linux Linux kernel>=4.16
Linux Linux kernel=4.10
Microsoft azl3 kernel 6.6.29.1-4
Microsoft cbl2 kernel 5.10.78.1-1
Microsoft kernel-tools-6.6.29.1-4.azl3.aarch64.rpm
Microsoft kernel-drivers-gpu-6.6.29.1-4.azl3.aarch64.rpm
Microsoft kernel-docs-6.6.29.1-4.azl3.aarch64.rpm
Microsoft kernel-drivers-accessibility-6.6.29.1-4.azl3.aarch64.rpm
Microsoft azl3 kernel 6.6.92.2-1
Microsoft cm1 kernel 5.10.60.1-1
Microsoft bpftool-6.6.29.1-4.azl3.aarch64.rpm
Microsoft kernel-devel-6.6.29.1-4.azl3.aarch64.rpm
Microsoft bpftool-6.6.29.1-4.azl3.x86_64.rpm
Microsoft python3-perf-6.6.29.1-4.azl3.aarch64.rpm
Microsoft kernel-6.6.29.1-4.azl3.aarch64.rpm
Microsoft python3-perf-6.6.29.1-4.azl3.x86_64.rpm
Microsoft kernel-drivers-sound-6.6.29.1-4.azl3.aarch64.rpm
Microsoft kernel-tools-6.6.29.1-4.azl3.x86_64.rpm
Microsoft kernel-docs-6.6.29.1-4.azl3.x86_64.rpm
Microsoft kernel-drivers-gpu-6.6.29.1-4.azl3.x86_64.rpm
Microsoft python3-perf-5.15.32.1-3.cm2.aarch64.rpm
Microsoft bpftool-5.15.32.1-3.cm2.aarch64.rpm
Microsoft kernel-devel-6.6.29.1-4.azl3.x86_64.rpm
Microsoft kernel-tools-5.15.32.1-3.cm2.aarch64.rpm
Microsoft kernel-debuginfo-5.15.32.1-3.cm2.aarch64.rpm
Microsoft kernel-drivers-accessibility-6.6.29.1-4.azl3.x86_64.rpm
Microsoft kernel-drivers-sound-6.6.29.1-4.azl3.x86_64.rpm
Microsoft kernel-drivers-sound-5.15.32.1-3.cm2.aarch64.rpm
Microsoft kernel-dtb-5.15.32.1-3.cm2.aarch64.rpm
Microsoft kernel-devel-5.15.32.1-3.cm2.aarch64.rpm
Microsoft kernel-debuginfo-5.15.32.1-3.cm2.x86_64.rpm
Microsoft kernel-drivers-accessibility-5.15.32.1-3.cm2.aarch64.rpm
Microsoft python3-perf-5.15.32.1-3.cm2.x86_64.rpm
Microsoft kernel-tools-5.15.32.1-3.cm2.x86_64.rpm
Microsoft kernel-drivers-sound-5.15.32.1-3.cm2.x86_64.rpm
Microsoft bpftool-5.15.32.1-3.cm2.x86_64.rpm
Microsoft kernel-devel-5.15.32.1-3.cm2.x86_64.rpm
Microsoft kernel-docs-5.15.32.1-3.cm2.x86_64.rpm
Microsoft kernel-drivers-accessibility-5.15.32.1-3.cm2.x86_64.rpm
Microsoft kernel-5.15.32.1-3.cm2.aarch64.rpm
Microsoft kernel-debuginfo-5.10.60.1-1.cm1.aarch64.rpm
Microsoft kernel-5.15.32.1-3.cm2.x86_64.rpm
Microsoft kernel-6.6.29.1-4.azl3.x86_64.rpm
Microsoft kernel-docs-5.15.32.1-3.cm2.aarch64.rpm
Microsoft kernel-devel-5.10.60.1-1.cm1.aarch64.rpm
Microsoft kernel-drivers-accessibility-5.10.60.1-1.cm1.aarch64.rpm
Microsoft kernel-dtb-5.10.60.1-1.cm1.aarch64.rpm
Microsoft kernel-drivers-sound-5.10.60.1-1.cm1.aarch64.rpm
Microsoft kernel-tools-5.10.60.1-1.cm1.aarch64.rpm
Microsoft kernel-5.10.60.1-1.cm1.aarch64.rpm
Microsoft kernel-docs-5.10.60.1-1.cm1.aarch64.rpm
Microsoft kernel-debuginfo-5.10.60.1-1.cm1.x86_64.rpm
Microsoft kernel-tools-5.10.60.1-1.cm1.x86_64.rpm
Microsoft kernel-oprofile-5.10.60.1-1.cm1.x86_64.rpm
Microsoft kernel-docs-5.10.60.1-1.cm1.x86_64.rpm
Microsoft kernel-drivers-sound-5.10.60.1-1.cm1.x86_64.rpm
Microsoft kernel-drivers-accessibility-5.10.60.1-1.cm1.x86_64.rpm
Microsoft kernel-devel-5.10.60.1-1.cm1.x86_64.rpm
Microsoft kernel-5.10.60.1-1.cm1.x86_64.rpm
debian/linux
5.10.223-15.10.262-16.1.176-16.1.180-16.12.94-16.12.101-17.1.8-17.1.8-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/kernel-rt to a version that resolves this vulnerability.

    Fixed in 0:4.18.0-193.13.2.rt13.65.el8_2
  2. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:4.18.0-193.13.2.el8_2
  3. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2

Event History

Jan 17, 2020
Data Sourced
via Red Hat·08:11 AM
DescriptionSeverityAffected Software
Jan 30, 2020
CVE Published
06:00 PM
Jan 31, 2020
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 25, 2020
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·12:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Sep 23, 2025
Data Sourced
via Launchpad·02:43 AM
Description
Jul 4, 2026
Data Sourced
via Ubuntu·10:55 AM
RemedyDescriptionSeverityAffected Software
Aug 17, 2026
Data Sourced
via Debian·11:49 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2019-3016?

CVE-2019-3016 has a medium severity rating due to the potential for a race condition in the KVM hypervisor.

2

How do I fix CVE-2019-3016?

To remediate CVE-2019-3016, update to the latest kernel version as specified in the official redhat or debian documentation.

3

Which versions of the Linux kernel are affected by CVE-2019-3016?

CVE-2019-3016 affects Linux kernel versions 4.10 and higher, including specific builds noted by Red Hat and Debian.

4

What impact does CVE-2019-3016 have on system security?

CVE-2019-3016 can lead to invalid address translations, potentially compromising the system's memory integrity.

5

Is CVE-2019-3016 exploited in the wild?

As of the latest information, there have been no known active exploits of CVE-2019-3016 in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203