CVE-2019-3016
Summary
| CVE | CVE-2019-3016 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-31 20:15:00 UTC |
| Updated | 2023-11-07 03:09:00 UTC |
| Description | In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
CONFIRM |
git.kernel.org |
Patch, Vendor Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree |
CONFIRM |
git.kernel.org |
Patch, Vendor Advisory |
| [FYI PATCH 0/5] Missing TLB flushes - Paolo Bonzini |
CONFIRM |
lore.kernel.org |
Vendor Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree |
CONFIRM |
git.kernel.org |
Patch, Vendor Advisory |
| USN-4300-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Debian -- Security Information -- DSA-4699-1 linux |
DEBIAN |
www.debian.org |
|
| oss-security - CVE-2019-3016: information leak within a KVM guest |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| USN-4301-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
CONFIRM |
git.kernel.org |
Patch, Vendor Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree |
CONFIRM |
git.kernel.org |
Patch, Vendor Advisory |
| [FYI PATCH 0/5] Missing TLB flushes - Paolo Bonzini |
|
lore.kernel.org |
|
| 1792167 – (CVE-2019-3016) CVE-2019-3016 kernel: kvm: Information leak within a KVM guest |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Kernel Live Patch Security Notice LSN-0065-1 ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| February 2020 Linux Kernel Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377065 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2020:0113)
- 900101 CBL-Mariner Linux Security Update for kernel 5.10.52.1
- 900303 CBL-Mariner Linux Security Update for kernel 5.10.57.1
- 900321 CBL-Mariner Linux Security Update for kernel 5.10.60.1
- 901473 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (6519-1)
- 903417 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3493)
- 905785 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3493-1)
- 906374 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (6519-2)