CVE-2019-3016 Information
Description
In a Linux KVM guest that has PV TLB enabled a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
http://packetstormsecurity.com/files/157233/Kernel-Live-Patch-Security-Notice-LSN-0065-1.html http://www.openwall.com/lists/oss-security/2020/01/30/4 https://bugzilla.redhat.com/show_bug.cgi?id=1792167 https://git.kernel.org/linus/1eff70a9abd46f175defafd29bc17ad456f398a7 https://git.kernel.org/linus/8c6de56a42e0c657955e12b882a81ef07d1d073e https://git.kernel.org/linus/917248144db5d7320655dbb41d3af0b8a0f3d589 https://git.kernel.org/linus/a6bd811f1209fe1c64c9f6fd578101d6436c6b6e https://git.kernel.org/linus/b043138246a41064527cf019a3d51d9f015e9796 https://lore.kernel.org/lkml/1580407316-11391-1-git-send-email-pbonzini@redhat.com/ https://security.netapp.com/advisory/ntap-20200313-0003/ https://usn.ubuntu.com/4300-1/ https://usn.ubuntu.com/4301-1/ https://www.debian.org/security/2020/dsa-4699
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
4.7
Share on: