Kernel: KVM: export MSR_IA32_TSX_CTRL to guest - incomplete fix for TAA (CVE-2019-11135)
Published Jul 13, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.48%
Description
A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is running on a host CPU affected by the TAA flaw (TAA_NO=0), but is not affected by the MDS issue (MDS_NO=1), the guest was to clear the affected buffers by using a VERW instruction mechanism. But when the MDS_NO=1 bit was exported to the guests, the guests did not use the VERW mechanism to clear the affected buffers. This issue affects guests running on Cascade Lake CPUs and requires that host has 'TSX' enabled. Confidentiality of data is the highest threat associated with this vulnerability.
Affected products
- Vendor n/a Product Linux Kernel Defaultn/a
- Version before 5.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Linux Kernel | n/a |
|
Configuration 1
- < 5.5
Configuration 2
- 6.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.18.1.el7
Fixed · RHSA-2020:0834
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1062.18.1.rt56.1044.el7
Fixed · RHSA-2020:0839
Red Hat Enterprise Linux 7.6 Extended Update Support
kernel-0:3.10.0-957.48.1.el7
Fixed · RHSA-2020:1465
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.5.1.el8_1
Fixed · RHSA-2020:0339
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.5.1.rt24.98.el8_1
Fixed · RHSA-2020:0328
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
kernel-0:3.10.0-957.48.1.el7
Fixed · RHSA-2020:1465
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.18.1.el7 | Fixed | RHSA-2020:0834 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1062.18.1.rt56.1044.el7 | Fixed | RHSA-2020:0839 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kernel-0:3.10.0-957.48.1.el7 | Fixed | RHSA-2020:1465 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.5.1.el8_1 | Fixed | RHSA-2020:0339 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.5.1.rt24.98.el8_1 | Fixed | RHSA-2020:0328 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | kernel-0:3.10.0-957.48.1.el7 | Fixed | RHSA-2020:1465 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/solutions/tsx-asynchronousabort
Red Hat mitigation
Please refer to the Red Hat Knowledgebase Transactional Synchronization Extensions (TSX) Asynchronous Abort article (https://access.redhat.com/solutions/tsx-asynchronousabort) for mitigation instructions.
References (8)
- https://access.redhat.com/security/cve/CVE-2019-19338 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1781514 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19338 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8959 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19338
- https://software.intel.com/security-software-guidance/insights/deep-dive-intel-transactional-synchronization-extensions-intel-tsx-asynchronous-abort x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19338
- https://www.openwall.com/lists/oss-security/2019/12/10/3 x_refsource_MISCMailing ListPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-19338 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1781514 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19338 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8959 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-19338 | ||
| https://software.intel.com/security-software-guidance/insights/deep-dive-intel-transactional-synchronization-extensions-intel-tsx-asynchronous-abort | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-19338 | ||
| https://www.openwall.com/lists/oss-security/2019/12/10/3 | x_refsource_MISCMailing ListPatchThird Party Advisory |
Change history (0)
No recorded changes yet.