There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html
http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html
http://www.openwall.com/lists/oss-security/2019/08/28/1
https://access.redhat.com/security/cve/cve-2019-14814
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14814
https://github.com/torvalds/linux/commit/7caac62ed598a196d6ddf8d9c121e12e082cac3a
https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html
https://security.netapp.com/advisory/ntap-20191031-0005/
https://usn.ubuntu.com/4157-1/
https://usn.ubuntu.com/4157-2/
https://usn.ubuntu.com/4162-1/
https://usn.ubuntu.com/4162-2/
https://usn.ubuntu.com/4163-1/
Source: MITRE
Published: 2019-09-20
Updated: 2019-09-24
Type: CWE-120
Base Score: 7.2
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
Impact Score: 10
Exploitability Score: 3.9
Severity: HIGH
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.8
Severity: HIGH
OR
OR
cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
145801 | CentOS 8 : kernel (CESA-2020:0339) | Nessus | CentOS Local Security Checks | critical |
144831 | EulerOS Virtualization 3.0.2.6 : kernel (EulerOS-SA-2021-1056) | Nessus | Huawei Local Security Checks | critical |
140379 | SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2491-1) | Nessus | SuSE Local Security Checks | critical |
137128 | OracleVM 3.4 : Unbreakable / etc (OVMSA-2020-0019) | Nessus | OracleVM Local Security Checks | high |
136485 | Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5676) | Nessus | Oracle Linux Local Security Checks | high |
136388 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5670) | Nessus | Oracle Linux Local Security Checks | high |
134486 | EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1197) | Nessus | Huawei Local Security Checks | critical |
134240 | Debian DLA-2114-1 : linux-4.9 security update | Nessus | Debian Local Security Checks | critical |
133591 | Oracle Linux 8 : kernel (ELSA-2020-0339) | Nessus | Oracle Linux Local Security Checks | critical |
133480 | RHEL 8 : kernel (RHSA-2020:0339) | Nessus | Red Hat Local Security Checks | critical |
133477 | RHEL 8 : kernel-rt (RHSA-2020:0328) | Nessus | Red Hat Local Security Checks | critical |
133162 | RHEL 7 : kernel-alt (RHSA-2020:0174) | Nessus | Red Hat Local Security Checks | high |
131845 | EulerOS 2.0 SP2 : kernel (EulerOS-SA-2019-2353) | Nessus | Huawei Local Security Checks | critical |
131474 | EulerOS Virtualization for ARM 64 3.0.3.0 : kernel (EulerOS-SA-2019-2309) | Nessus | Huawei Local Security Checks | high |
131120 | SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2984-1) | Nessus | SuSE Local Security Checks | critical |
130950 | SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2950-1) (SACK Panic) | Nessus | SuSE Local Security Checks | critical |
130949 | SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2949-1) | Nessus | SuSE Local Security Checks | critical |
130815 | EulerOS 2.0 SP8 : kernel (EulerOS-SA-2019-2106) | Nessus | Huawei Local Security Checks | critical |
130751 | Slackware 14.2 : Slackware 14.2 kernel (SSA:2019-311-01) | Nessus | Slackware Local Security Checks | critical |
130736 | EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2274) | Nessus | Huawei Local Security Checks | critical |
130663 | EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-2201) | Nessus | Huawei Local Security Checks | critical |
130163 | SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2738-1) | Nessus | SuSE Local Security Checks | critical |
130152 | Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4163-1) | Nessus | Ubuntu Local Security Checks | critical |
130151 | Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4162-1) | Nessus | Ubuntu Local Security Checks | critical |
130147 | Ubuntu 18.04 LTS : Linux kernel (HWE) vulnerabilities (USN-4157-2) | Nessus | Ubuntu Local Security Checks | critical |
130003 | Ubuntu 19.04 : Linux kernel vulnerabilities (USN-4157-1) | Nessus | Ubuntu Local Security Checks | critical |
129845 | SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2648-1) | Nessus | SuSE Local Security Checks | critical |
129361 | Debian DLA-1930-1 : linux security update | Nessus | Debian Local Security Checks | critical |
129345 | openSUSE Security Update : the Linux Kernel (openSUSE-2019-2181) | Nessus | SuSE Local Security Checks | critical |
129339 | openSUSE Security Update : the Linux Kernel (openSUSE-2019-2173) | Nessus | SuSE Local Security Checks | critical |
129157 | SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2424-1) | Nessus | SuSE Local Security Checks | critical |
129156 | SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2414-1) | Nessus | SuSE Local Security Checks | critical |
129154 | SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2019:2412-1) | Nessus | SuSE Local Security Checks | critical |
128485 | Fedora 29 : kernel / kernel-headers / kernel-tools (2019-97380355ae) | Nessus | Fedora Local Security Checks | critical |
128481 | Fedora 30 : kernel / kernel-headers / kernel-tools (2019-4c91a2f76e) | Nessus | Fedora Local Security Checks | critical |