CVE-2019-14821: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • Linux Linux Kernel: from 2.6.27, up to and including 3.15.10; from 3.16, before 3.16.74 (fixed in 3.16.74); from 4.4, before 4.4.194 (fixed in 4.4.194); from 4.9, before 4.9.194 (fixed in 4.9.194); from 4.14, before 4.14.146 (fixed in 4.14.146); from 4.19, before 4.19.75 (fixed in 4.19.75); …
  • Netapp Aff a700s Firmware: affected versions not specified
  • Netapp Data Availability Services: affected versions not specified
  • Netapp h300e Firmware: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500e Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h610s Firmware: affected versions not specified
  • Netapp h700e Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle SD-WAN Edge: version 7.3 only; version 8.0 only; version 8.1 only; version 8.2 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.7 only
  • Red Hat Enterprise Linux For Real Time: version 7 only; version 8 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.7 only
  • and 3 more

Published 2019-09-19. Last modified 2026-06-17.