Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Oracle Linux: CVE-2019-7222: ELSA-2019-2029: kernel security, bug fix, and enhancement update (IMPORTANT) (Multiple Advisories)

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
Published
Feb 7, 2019
Added
Aug 15, 2019
Modified
Dec 3, 2025

Description

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
An information leakage issue was found in the way Linux kernel's KVM hypervisor handled page fault exceptions while emulating instructions like VMXON, VMCLEAR, VMPTRLD, and VMWRITE with memory address as an operand. It occurs if the operand is a mmio address, as the returned exception object holds uninitialized stack memory contents. A guest user/process could use this flaw to leak host's stack memory contents to a guest.

Solutions

oracle-linux-upgrade-kerneloracle-linux-upgrade-kernel-uek
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.