vulnerability

Oracle Linux: CVE-2019-7222: ELSA-2019-2029: kernel security, bug fix, and enhancement update (IMPORTANT) (Multiple Advisories)

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
Published
Feb 7, 2019
Added
Aug 15, 2019
Modified
Dec 3, 2025

Description

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
An information leakage issue was found in the way Linux kernel's KVM hypervisor handled page fault exceptions while emulating instructions like VMXON, VMCLEAR, VMPTRLD, and VMWRITE with memory address as an operand. It occurs if the operand is a mmio address, as the returned exception object holds uninitialized stack memory contents. A guest user/process could use this flaw to leak host's stack memory contents to a guest.

Solutions

oracle-linux-upgrade-kerneloracle-linux-upgrade-kernel-uek
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.