Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian 9: DSA-4531-1 Critical: Linux Kernel Privilege Escalation

debian
Calendar Grey September 25, 2019
Debian Logo
Debian Security Advisory DSA-4531-1 addresses kernel vulnerabilities that could compromise system integrity. Users are urged to update to patched kernel versions promptly
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

CVE-2019-14821

Matt Delco reported a race condition in KVM's coalesced MMIO
facility, which could lead to out-of-bounds access in the kernel.
A local attacker permitted to access /dev/kvm could use this to
cause a denial of service (memory corruption or crash) or possibly
for privilege escalation.

CVE-2019-14835

Peter Pi of Tencent Blade Team discovered a missing bounds check
in vhost_net, the network back-end driver for KVM hosts, leading
to a buffer overflow when the host begins live migration of a VM.
An attacker in control of a VM could use this to cause a denial of
service (memory corruption or crash) or possibly for privilege
escalation on the host.

CVE-2019-15117

Hui Peng and Mathias Payer reported a missing bounds check in the
usb-audio driver's descriptor parsing code, leading to a buffer
over-read. An attacker able to add USB devices could possibly use
this to cause a denial of service (crash).

CVE-2019-15118

Hui Peng and Mathi...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2019-14821 CVE-2019-14835 CVE-2019-15117 CVE-2019-15118

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here