CVE-2019-3016

In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.10:*:*:*:*:*:*:*

History

07 Nov 2023, 03:09

Type Values Removed Values Added
References
  • {'url': 'https://lore.kernel.org/lkml/1580407316-11391-1-git-send-email-pbonzini@redhat.com/', 'name': 'https://lore.kernel.org/lkml/1580407316-11391-1-git-send-email-pbonzini@redhat.com/', 'tags': ['Vendor Advisory'], 'refsource': 'CONFIRM'}
  • () https://lore.kernel.org/lkml/1580407316-11391-1-git-send-email-pbonzini%40redhat.com/ -

Information

Published : 2020-01-31 20:15

Updated : 2024-02-28 17:28


NVD link : CVE-2019-3016

Mitre link : CVE-2019-3016

CVE.ORG link : CVE-2019-3016


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor