CVE-2019-14835 Vulnerability Details

  /     /     /  

CVE-2019-14835 Metadata Quick Info

CVE Published: 17/09/2019 | CVE Updated: 05/08/2024 | CVE Year: 2019
Source: redhat | Vendor: Linux Kernel | Product: Linux kernel
Status : PUBLISHED

CVE-2019-14835 Description

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel\'s vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-120
CWE Name: CWE-120
Source: Linux Kernel

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).