Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian LTS: DLA-1940-1 Critical: linux-4.9 Denial of Service Risks

debian lts
Calendar Grey October 1, 2019
Dist Debian Esm H88
Explore the latest security patches for linux-4.9 that tackle various weaknesses impacting Debian installations.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

Matt Delco reported a race condition in KVM's coalesced MMIO
facility, which could lead to out-of-bounds access in the kernel.
A local attacker permitted to access /dev/kvm could use this to
cause a denial of service (memory corruption or crash) or possibly
for privilege escalation.

CVE-2019-14835

Peter Pi of Tencent Blade Team discovered a missing bounds check
in vhost_net, the network back-end driver for KVM hosts, leading
to a buffer overflow when the host begins live migration of a VM.
An attacker in control of a VM could use this to cause a denial of
service (memory corruption or crash) or possibly for privilege
escalation on the host.

CVE-2019-15117

Hui Peng and Mathias Payer reported a missing bounds check in the
usb-audio driver's descriptor parsing code, leading to a buffer
over-read. An attacker able to add USB devices could possibly use
this to cause a denial of service (crash).

CVE-2019-15118

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: linux-4.9
Version: 4.9.189-3+deb9u1~deb8u1
CVE ID: CVE-2019-14821 CVE-2019-14835 CVE-2019-15117 CVE-2019-15118

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here