Kernel: KVM: leak of uninitialized stack contents to guest
Published Mar 17, 2019
5.5
MEDIUMCVSS 3.1
EPSS 0.68%
Description
The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
Affected products
No data.
Configuration 1
- ≤ 4.20.5
Configuration 2
- 28
- 29
Configuration 4
- 8.0
Configuration 5
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 6
- n/a
- n/a
Configuration 7
- 8.0
- 7.0
- 8.1
- 8.2
- 8.4
- 8.6
- 7
- 8
- 7
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 7.0
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 7.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.el7
Fixed · RHSA-2019:2029
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1062.rt56.1022.el7
Fixed · RHSA-2019:2043
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.el8
Fixed · RHSA-2019:3517
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.rt24.93.el8
Fixed · RHSA-2019:3309
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.el7 | Fixed | RHSA-2019:2029 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1062.rt56.1022.el7 | Fixed | RHSA-2019:2043 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.el8 | Fixed | RHSA-2019:3517 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.rt24.93.el8 | Fixed | RHSA-2019:3309 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG 2. This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 7. Future kernel updates for Red Hat Enterprise Linux 7 may address this issue. Note:- Impact on Red Hat Enterprise Linux 7 kernel is limited, as it requires that nested virtualization feature is enabled on a system. Nested Virtualization feature is available only as - Technology Preview.
References (29)
- http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00042.html vendor-advisoryx_refsource_SUSEBroken LinkMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/151712/KVM-kvm_inject_page_fault-Uninitialized-Memory-Leak.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/02/18/2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/106963 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2029 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2043 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3309 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3517 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-7222 Vendor Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1759 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1671930 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=353c0956a618a07ba4bbe7ad00ff29fe70e8412a x_refsource_CONFIRMPatchVendor Advisory
- https://github.com/torvalds/linux/commits/master/arch/x86/kvm x_refsource_MISCThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KDOXCX3QFVWYXH5CQMGDDE7H6MUG5XGG/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y2HMABEMJDPA6LPCBE5WIEZXUKY7DLTN/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-7222
- https://security.netapp.com/advisory/ntap-20190404-0002/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/3930-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3930-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3931-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3931-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3932-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3932-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3933-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3933-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-7222
Change history (0)
No recorded changes yet.