CVE-2019-14835

Published: 17 September 2019

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.

From the Ubuntu security team

Peter Pi discovered a buffer overflow in the virtio network backend (vhost_net) implementation in the Linux kernel. An attacker in a guest may be able to use this to cause a denial of service (host OS crash) or possibly execute arbitrary code in the host OS.

Priority

High

CVSS 3 base score: 7.8

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-64.73)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-164.192)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (3.13.0-173.224)
Patches:
Introduced by 3a4d5c94e959359ece6d6b55045c3f046677f55c
Fixed by 060423bfdee3f8bc6e2c1bac97de24d5415e2bc4
linux-aws
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1050.52)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-1094.105)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (4.4.0-1054.58)
linux-aws-5.0
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(5.0.0-1021.24~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-aws-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1050.52~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-azure
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (5.0.0-1020.21~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1059.64)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (4.15.0-1059.64~14.04.1)
linux-azure-5.3
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(5.3.0-1007.8~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-azure-edge
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (5.0.0-1020.21~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1059.64)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gcp
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1044.70)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1044.46)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gcp-5.3
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(5.3.0-1008.9~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gcp-edge
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1044.70)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gke-4.15
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1044.46)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-gke-5.0
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (5.0.0-1017.17~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (5.0.0-29.31~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-64.73~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-hwe-edge
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Ignored
(was pending \[5.3.0-19.20~18.04.2\] now end-of-life)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-64.73~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-kvm
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1046.46)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-1058.65)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-lts-trusty
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-lts-xenial
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr)
Released (4.4.0-164.192~14.04.1)
linux-oem
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1056.65)
Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(was needs-triage now end-of-life)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-oem-5.4
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-oem-osp1
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (5.0.0-1022.24)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-oracle
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1025.28)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.15.0-1025.28~16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-oracle-5.0
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(5.0.0-1007.12~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-raspi2
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1047.51)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-1122.131)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-raspi2-5.3
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(5.3.0-1017.19~18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

linux-snapdragon
Launchpad, Ubuntu, Debian
Upstream
Released (5.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1064.71)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (4.4.0-1126.132)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist