CVE-2019-6974: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 16.5% chance of exploitation in the next 30 days.

In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only
  • F5 BIG-IP Access Policy Manager: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Advanced Firewall Manager: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Analytics: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Application Acceleration Manager: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Application Security Manager: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Edge Gateway: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Fraud Protection Service: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Global Traffic Manager: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Link Controller: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Local Traffic Manager: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Policy Enforcement Manager: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • F5 BIG-IP Webaccelerator: from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; from 15.0.0, before 15.1.0 (fixed in 15.1.0)
  • Linux Linux Kernel: from 3.10, before 3.16.64 (fixed in 3.16.64); from 3.17, before 3.18.136 (fixed in 3.18.136); from 3.19, before 4.4.176 (fixed in 4.4.176); from 4.5, before 4.9.156 (fixed in 4.9.156); from 4.10, before 4.14.99 (fixed in 4.14.99); from 4.15, before 4.19.21 (fixed in 4.19.21); …
  • Red Hat Enterprise Linux: version 7.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.5 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2019-02-15. Last modified 2026-06-17.