kernel: vhost-net: guest to host kernel escape during migration
Published Sep 17, 2019
7.8
HIGHCVSS 3.1
EPSS 0.62%
Description
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
Affected products
-
- Version from version 2.6.34 to 5.2.xStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linux Kernel | Linux kernel | n/a |
|
Configuration 1
- ≥ 2.6.34 · < 3.16.74
- ≥ 4.4 · < 4.4.193
- ≥ 4.9 · < 4.9.193
- ≥ 4.14 · < 4.14.144
- ≥ 4.19 · < 4.19.73
- ≥ 5.2 · < 5.2.15
- 5.3
Configuration 2
- 12.04
- 14.04
- 16.04
- 18.04
- 19.04
Configuration 3
- 8.0
- 9.0
- 10.0
Configuration 4
- 29
- 30
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Configuration 16
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 17
- 3.11
- 8.0
- 6.0
- 7.0
- 7.5
- 7.6
- 7.7
- 7
- 8
- 6.0
- 7.0
- 7.6
- 6.5
- 6.6
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 6.0
- 7.0
Configuration 18
- 4.0
- 4.0
Running on/with
- 7.0
Configuration 19
- v600r009c00
- v600r009c10spc200
- v600r008c10spc300
- v600r008c20
- 6.5.0
- 6.5.0.spc100.b210
- 6.5.1rc1.b060
- 6.5.1rc1.b080
- 6.5.rc2.b050
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.23.1.el6
Fixed · RHSA-2019:2863
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.96.2.el6
Fixed · RHSA-2019:2901
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.81.2.el6
Fixed · RHSA-2019:2869
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.1.2.el7
Fixed · RHSA-2019:2829
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.13.1.el7a
Fixed · RHSA-2019:2862
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1062.1.2.rt56.1025.el7
Fixed · RHSA-2019:2830
Red Hat Enterprise Linux 7
kpatch-patch
Fixed · RHSA-2019:2854
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.82.1.el7
Fixed · RHSA-2019:2899
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.82.1.el7
Fixed · RHSA-2019:2899
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.82.1.el7
Fixed · RHSA-2019:2899
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.69.1.el7
Fixed · RHSA-2019:2900
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.69.1.el7
Fixed · RHSA-2019:2900
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.69.1.el7
Fixed · RHSA-2019:2900
Red Hat Enterprise Linux 7.4 Advanced Update Support
kernel-0:3.10.0-693.59.1.el7
Fixed · RHSA-2019:2867
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
kernel-0:3.10.0-693.59.1.el7
Fixed · RHSA-2019:2867
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
kernel-0:3.10.0-693.59.1.el7
Fixed · RHSA-2019:2867
Red Hat Enterprise Linux 7.5 Extended Update Support
kernel-0:3.10.0-862.41.2.el7
Fixed · RHSA-2019:2866
Red Hat Enterprise Linux 7.6 Extended Update Support
kernel-0:3.10.0-957.35.2.el7
Fixed · RHSA-2019:2864
Red Hat Enterprise Linux 7.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2019:2865
Red Hat Enterprise Linux 8
kernel-0:4.18.0-80.11.2.el8_0
Fixed · RHSA-2019:2827
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-80.11.2.rt9.157.el8_0
Fixed · RHSA-2019:2828
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.5-20190920.0.el7_7
Fixed · RHSA-2019:2889
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
kernel-0:3.10.0-957.35.2.el7
Fixed · RHSA-2019:2864
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-virtualization-host-0:4.2-20190919.0.el7_6
Fixed · RHSA-2019:2924
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.23.1.el6 | Fixed | RHSA-2019:2863 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.96.2.el6 | Fixed | RHSA-2019:2901 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.81.2.el6 | Fixed | RHSA-2019:2869 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.1.2.el7 | Fixed | RHSA-2019:2829 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.13.1.el7a | Fixed | RHSA-2019:2862 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1062.1.2.rt56.1025.el7 | Fixed | RHSA-2019:2830 |
| Red Hat Enterprise Linux 7 | kpatch-patch | Fixed | RHSA-2019:2854 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.82.1.el7 | Fixed | RHSA-2019:2899 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.82.1.el7 | Fixed | RHSA-2019:2899 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.82.1.el7 | Fixed | RHSA-2019:2899 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.69.1.el7 | Fixed | RHSA-2019:2900 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.69.1.el7 | Fixed | RHSA-2019:2900 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.69.1.el7 | Fixed | RHSA-2019:2900 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | kernel-0:3.10.0-693.59.1.el7 | Fixed | RHSA-2019:2867 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | kernel-0:3.10.0-693.59.1.el7 | Fixed | RHSA-2019:2867 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | kernel-0:3.10.0-693.59.1.el7 | Fixed | RHSA-2019:2867 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | kernel-0:3.10.0-862.41.2.el7 | Fixed | RHSA-2019:2866 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kernel-0:3.10.0-957.35.2.el7 | Fixed | RHSA-2019:2864 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2019:2865 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-80.11.2.el8_0 | Fixed | RHSA-2019:2827 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-80.11.2.rt9.157.el8_0 | Fixed | RHSA-2019:2828 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.5-20190920.0.el7_7 | Fixed | RHSA-2019:2889 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | kernel-0:3.10.0-957.35.2.el7 | Fixed | RHSA-2019:2864 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-virtualization-host-0:4.2-20190919.0.el7_6 | Fixed | RHSA-2019:2924 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/security/vulnerabilities/kernel-vhost
Red Hat mitigation
For mitigation related information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/security/vulnerabilities/kernel-vhost
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.62% (0.00622) | 47.99th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.63% (0.00627) | 45.11th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00038) | 8.45th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00095) | 41.74th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00069) | 28.22th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.43% (0.09432) | 87.12th | v2 (v2022.01.01) |
| Feb 3, 2022 | 28.19% (0.28193) | 96.46th | v1 |
| Jan 6, 2022 | 28.19% (0.28193) | 96.42th | v1 |
| Sep 1, 2021 | 8.05% (0.08047) | 92.52th | v1 |
| Apr 14, 2021 | 8.05% (0.08047) | 0.00th | v1 |
References (45)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/154572/Kernel-Live-Patch-Security-Notice-LSN-0056-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-qemu-en x_refsource_CONFIRMThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/09/24/1 mailing-listx_refsource_MLISTMailing List
- http://www.openwall.com/lists/oss-security/2019/10/03/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/09/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/09/7 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHBA-2019:2824 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2827 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2828 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2829 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2830 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2854 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2862 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2863 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2864 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2865 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2866 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2867 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2869 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2889 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2899 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2900 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2901 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2924 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-14835 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/kernel-vhost
- https://bugzilla.redhat.com/show_bug.cgi?id=1750727 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14835 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQFY6JYFIQ2VFQ7QCSXPWTUL5ZDNCJL5/ vendor-advisoryx_refsource_FEDORAMailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3QNMPENPFEGVTOFPSNOBL7JEIJS25P/ vendor-advisoryx_refsource_FEDORAMailing List
- https://nvd.nist.gov/vuln/detail/CVE-2019-14835
- https://seclists.org/bugtraq/2019/Nov/11 mailing-listx_refsource_BUGTRAQIssue TrackingMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Sep/41 mailing-listx_refsource_BUGTRAQIssue TrackingMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191031-0005/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4135-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4135-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14835
- https://www.debian.org/security/2019/dsa-4531 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openwall.com/lists/oss-security/2019/09/17/1 x_refsource_MISCExploitMailing ListPatchThird Party Advisory
Change history (0)
No recorded changes yet.