CVE-2019-14816

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.

References

https://www.openwall.com/lists/oss-security/2019/08/28/1

https://github.com/torvalds/linux/commit/7caac62ed598a196d6ddf8d9c121e12e082cac3

http://www.openwall.com/lists/oss-security/2019/08/28/1

https://access.redhat.com/security/cve/cve-2019-14816

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14816

https://lists.fedoraproject.org/archives/list/[email protected]/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/

https://lists.fedoraproject.org/archives/list/[email protected]/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/

http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html

http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html

https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html

https://usn.ubuntu.com/4157-1/

https://usn.ubuntu.com/4157-2/

https://usn.ubuntu.com/4162-1/

https://usn.ubuntu.com/4163-1/

https://usn.ubuntu.com/4163-2/

https://usn.ubuntu.com/4162-2/

http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html

https://security.netapp.com/advisory/ntap-20191031-0005/

https://seclists.org/bugtraq/2019/Nov/11

http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html

https://access.redhat.com/errata/RHSA-2020:0174

https://access.redhat.com/errata/RHSA-2020:0204

https://access.redhat.com/errata/RHSA-2020:0328

https://access.redhat.com/errata/RHSA-2020:0339

https://access.redhat.com/errata/RHSA-2020:0375

https://access.redhat.com/errata/RHSA-2020:0374

https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html

https://access.redhat.com/errata/RHSA-2020:0653

https://access.redhat.com/errata/RHSA-2020:0661

https://access.redhat.com/errata/RHSA-2020:0664

Details

Source: MITRE

Published: 2019-09-20

Updated: 2021-11-02

Type: CWE-787

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_for_real_time:7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_for_real_time:8:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:8:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.4:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.4:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server:8.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_tus:7.7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:messaging_realtime_grid:2.0:*:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 4

OR

cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*

cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*

cpe:2.3:a:netapp:service_processor:-:*:*:*:*:*:*:*

cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*

cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*

Configuration 5

AND

OR

cpe:2.3:o:netapp:a700s_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:a700s:-:*:*:*:*:*:*:*

Configuration 6

AND

OR

cpe:2.3:o:netapp:a320_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:a320:-:*:*:*:*:*:*:*

Configuration 7

AND

OR

cpe:2.3:o:netapp:c190_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:c190:-:*:*:*:*:*:*:*

Configuration 8

AND

OR

cpe:2.3:o:netapp:a220_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:a220:-:*:*:*:*:*:*:*

Configuration 9

AND

OR

cpe:2.3:o:netapp:fas2720_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:fas2720:-:*:*:*:*:*:*:*

Configuration 10

AND

OR

cpe:2.3:o:netapp:fas2750_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:fas2750:-:*:*:*:*:*:*:*

Configuration 11

AND

OR

cpe:2.3:o:netapp:a800_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:a800:-:*:*:*:*:*:*:*

Configuration 12

AND

OR

cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 13

AND

OR

cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 14

AND

OR

cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 15

AND

OR

cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*

Configuration 16

AND

OR

cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*

Configuration 17

AND

OR

cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*

Configuration 18

AND

OR

cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 19

AND

OR

cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 20

AND

OR

cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*

OR

cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*

Configuration 21

OR

cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

Configuration 22

OR

cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Tenable Plugins

View all (51 total)

IDNameProductFamilySeverity
145801CentOS 8 : kernel (CESA-2020:0339)NessusCentOS Local Security Checks
critical
144831EulerOS Virtualization 3.0.2.6 : kernel (EulerOS-SA-2021-1056)NessusHuawei Local Security Checks
critical
143971NewStart CGSL CORE 5.05 / MAIN 5.05 : kernel Multiple Vulnerabilities (NS-SA-2020-0108)NessusNewStart CGSL Local Security Checks
critical
140379SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2491-1)NessusSuSE Local Security Checks
critical
137128OracleVM 3.4 : Unbreakable / etc (OVMSA-2020-0019)NessusOracleVM Local Security Checks
high
136485Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5676)NessusOracle Linux Local Security Checks
medium
136388Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5670)NessusOracle Linux Local Security Checks
high
135762NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2020-0014)NessusNewStart CGSL Local Security Checks
critical
135252RHEL 7 : kernel (RHSA-2020:1347)NessusRed Hat Local Security Checks
high
135248RHEL 6 : kernel-rt (RHSA-2020:1353)NessusRed Hat Local Security Checks
high
135088RHEL 7 : kernel (RHSA-2020:1266)NessusRed Hat Local Security Checks
high
134486EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1197)NessusHuawei Local Security Checks
critical
134320NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2020-0010)NessusNewStart CGSL Local Security Checks
critical
134262RHEL 7 : kernel (RHSA-2020:0664)NessusRed Hat Local Security Checks
critical
134260RHEL 7 : kernel (RHSA-2020:0661)NessusRed Hat Local Security Checks
high
134259RHEL 7 : kernel (RHSA-2020:0653)NessusRed Hat Local Security Checks
critical
134240Debian DLA-2114-1 : linux-4.9 security updateNessusDebian Local Security Checks
critical
134087CentOS 7 : kernel (CESA-2020:0374)NessusCentOS Local Security Checks
critical
133591Oracle Linux 8 : kernel (ELSA-2020-0339)NessusOracle Linux Local Security Checks
critical
133538Scientific Linux Security Update : kernel on SL7.x x86_64 (20200205)NessusScientific Linux Local Security Checks
critical
133514Oracle Linux 7 : kernel (ELSA-2020-0374)NessusOracle Linux Local Security Checks
critical
133508CentOS 7 : kernel (CESA-2020:0375) (deprecated)NessusCentOS Local Security Checks
critical
133484RHEL 7 : kernel-rt (RHSA-2020:0375)NessusRed Hat Local Security Checks
critical
133483RHEL 7 : kernel (RHSA-2020:0374)NessusRed Hat Local Security Checks
critical
133480RHEL 8 : kernel (RHSA-2020:0339)NessusRed Hat Local Security Checks
critical
133477RHEL 8 : kernel-rt (RHSA-2020:0328)NessusRed Hat Local Security Checks
critical
133221RHEL 8 : kernel (RHSA-2020:0204)NessusRed Hat Local Security Checks
critical
133162RHEL 7 : kernel-alt (RHSA-2020:0174)NessusRed Hat Local Security Checks
high
131845EulerOS 2.0 SP2 : kernel (EulerOS-SA-2019-2353)NessusHuawei Local Security Checks
critical
131474EulerOS Virtualization for ARM 64 3.0.3.0 : kernel (EulerOS-SA-2019-2309)NessusHuawei Local Security Checks
critical
131120SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2984-1)NessusSuSE Local Security Checks
critical
130950SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2950-1) (SACK Panic)NessusSuSE Local Security Checks
critical
130949SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2949-1)NessusSuSE Local Security Checks
critical
130815EulerOS 2.0 SP8 : kernel (EulerOS-SA-2019-2106)NessusHuawei Local Security Checks
critical
130751Slackware 14.2 : Slackware 14.2 kernel (SSA:2019-311-01)NessusSlackware Local Security Checks
critical
130736EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2274)NessusHuawei Local Security Checks
critical
130663EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-2201)NessusHuawei Local Security Checks
critical
130163SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2738-1)NessusSuSE Local Security Checks
critical
130152Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4163-1)NessusUbuntu Local Security Checks
critical
130151Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4162-1)NessusUbuntu Local Security Checks
critical
130147Ubuntu 18.04 LTS : Linux kernel (HWE) vulnerabilities (USN-4157-2)NessusUbuntu Local Security Checks
critical
130003Ubuntu 19.04 : Linux kernel vulnerabilities (USN-4157-1)NessusUbuntu Local Security Checks
critical
129845SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2648-1)NessusSuSE Local Security Checks
critical
129361Debian DLA-1930-1 : linux security updateNessusDebian Local Security Checks
critical
129345openSUSE Security Update : the Linux Kernel (openSUSE-2019-2181)NessusSuSE Local Security Checks
critical
129339openSUSE Security Update : the Linux Kernel (openSUSE-2019-2173)NessusSuSE Local Security Checks
critical
129157SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2424-1)NessusSuSE Local Security Checks
critical
129156SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2414-1)NessusSuSE Local Security Checks
critical
129154SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2019:2412-1)NessusSuSE Local Security Checks
critical
128485Fedora 29 : kernel / kernel-headers / kernel-tools (2019-97380355ae)NessusFedora Local Security Checks
critical
128481Fedora 30 : kernel / kernel-headers / kernel-tools (2019-4c91a2f76e)NessusFedora Local Security Checks
critical