Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-7222

Опубликовано: 07 фев. 2019
Источник: redhat
CVSS3: 2.8

Описание

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

An information leakage issue was found in the way Linux kernel's KVM hypervisor handled page fault exceptions while emulating instructions like VMXON, VMCLEAR, VMPTRLD, and VMWRITE with memory address as an operand. It occurs if the operand is a mmio address, as the returned exception object holds uninitialized stack memory contents. A guest user/process could use this flaw to leak host's stack memory contents to a guest.

Отчет

This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG 2. This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 7. Future kernel updates for Red Hat Enterprise Linux 7 may address this issue. Note:- Impact on Red Hat Enterprise Linux 7 kernel is limited, as it requires that nested virtualization feature is enabled on a system. Nested Virtualization feature is available only as - Technology Preview.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise MRG 2kernel-rtNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2019:204307.08.2019
Red Hat Enterprise Linux 7kernelFixedRHSA-2019:202906.08.2019
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2019:330905.11.2019
Red Hat Enterprise Linux 8kernelFixedRHSA-2019:351705.11.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1671930Kernel: KVM: leak of uninitialized stack contents to guest

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

CVSS3: 5.5
nvd
больше 6 лет назад

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

CVSS3: 5.5
debian
больше 6 лет назад

The KVM implementation in the Linux kernel through 4.20.5 has an Infor ...

CVSS3: 5.5
github
больше 3 лет назад

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость ядра операционной системы Linux, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

2.8 Low

CVSS3