In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
2019-02-15T15:29:00.250
2024-11-21T04:47:20.457
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | linux | linux_kernel | < 3.16.64 | Yes |
| Operating System | linux | linux_kernel | < 3.18.136 | Yes |
| Operating System | linux | linux_kernel | < 4.4.176 | Yes |
| Operating System | linux | linux_kernel | < 4.9.156 | Yes |
| Operating System | linux | linux_kernel | < 4.14.99 | Yes |
| Operating System | linux | linux_kernel | < 4.19.21 | Yes |
| Operating System | linux | linux_kernel | < 4.20.8 | Yes |
| Operating System | debian | debian_linux | 8.0 | Yes |
| Operating System | canonical | ubuntu_linux | 12.04 | Yes |
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.10 | Yes |
| Application | f5 | big-ip_access_policy_manager | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_access_policy_manager | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_analytics | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_analytics | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_analytics | < 15.1.0 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_application_security_manager | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_application_security_manager | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_application_security_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_edge_gateway | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_edge_gateway | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_edge_gateway | < 15.1.0 | Yes |
| Application | f5 | big-ip_fraud_protection_service | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_fraud_protection_service | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_fraud_protection_service | < 15.1.0 | Yes |
| Application | f5 | big-ip_global_traffic_manager | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_global_traffic_manager | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_global_traffic_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_link_controller | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_link_controller | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_link_controller | < 15.1.0 | Yes |
| Application | f5 | big-ip_local_traffic_manager | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_local_traffic_manager | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_local_traffic_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | < 15.1.0 | Yes |
| Application | f5 | big-ip_webaccelerator | ≤ 13.1.1 | Yes |
| Application | f5 | big-ip_webaccelerator | ≤ 14.1.0 | Yes |
| Application | f5 | big-ip_webaccelerator | < 15.1.0 | Yes |
| Application | redhat | openshift_container_platform | 3.11 | Yes |
| Operating System | redhat | enterprise_linux | 7.0 | Yes |
| Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
| Operating System | redhat | enterprise_linux_eus | 7.5 | Yes |
| Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
| Operating System | redhat | enterprise_linux_server_aus | 7.4 | Yes |
| Operating System | redhat | enterprise_linux_server_aus | 7.6 | Yes |
| Operating System | redhat | enterprise_linux_server_eus | 7.6 | Yes |
| Operating System | redhat | enterprise_linux_server_tus | 7.4 | Yes |
| Operating System | redhat | enterprise_linux_server_tus | 7.6 | Yes |
| Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |