VDB
GCVE-VVD-MAGEIA-2019-170
GCVE-VVD-MAGEIA-2019-170
Advisory Published
This kernel update is based on the upstream 4.14.116 and fixes at least
the following security issues:
A flaw was found in the Linux kernel's vfio interface implementation that
permits violation of the user's locked memory limit. If a device is bound
to a vfio driver, such as vfio-pci, and the local attacker is
administratively granted ownership of the device, it may cause a system
memory exhaustion and thus a denial of service (DoS) (CVE-2019-3882).
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable
out-of-bounds speculation on pointer arithmetic in various cases, including
cases of different branches with different state or limits to sanitize,
leading to side-channel attacks (CVE-2019-7308).
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the
Linux kernel before 5.0.8 has multiple race conditions (CVE-2019-11486).
The coredump implementation in the Linux kernel before 5.0.10 does not use
locking or other mechanisms to prevent vma layout or vma flags changes while
it runs, which allows local users to obtain sensitive information, cause a
denial of service, or possibly have unspecified other impact by triggering
a race condition with mmget_not_zero or get_task_mm calls (CVE-2019-11599).
WireGuard has been updated to 0.0.20190406.
For other uptstream fixes in this update, see the referenced changelogs.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | kernel-userspace-headers | 0 (affected), 4.14.116-1.mga6 (unaffected), 0 (affected), 4.14.116-1.mga6 (unaffected) | — |
| Mageia | rpm | 0 (affected), 4.13.1-3.3.mga6 (unaffected) | — |
| Mageia | kernel | 0 (affected), 4.14.116-1.mga6 (unaffected), 0 (affected), 4.14.116-1.mga6 (unaffected) | — |
| Mageia | kmod-virtualbox | 0 (affected), 6.0.6-2.mga6 (unaffected), 0 (affected), 6.0.6-2.mga6 (unaffected) | — |
| Mageia | wireguard-tools | 0 (affected), 0.0.20190406-1.mga6 (unaffected), 0 (affected), 0.0.20190406-1.mga6 (unaffected) | — |
| Mageia | kmod-xtables-addons | 0 (affected), 2.13-84.mga6 (unaffected), 0 (affected), 2.13-84.mga6 (unaffected) | — |
| Mageia | kmod-vboxadditions | 0 (affected), 6.0.6-2.mga6 (unaffected), 0 (affected), 6.0.6-2.mga6 (unaffected) | — |
Aliases
Transitive aliases
GHSA-4wh7-45g5-wcc8EUVD-2018-8672CVE-2018-16882VVD-MAGEIA-2019-107VVD-MAGEIA-2018-487BDU:2019-03298GHSA-xw3f-9qfw-v43fEUVD-2018-11773CVE-2018-19985CVE-2018-1128BDU:2019-01409CVE-2018-19824CVE-2018-1129GHSA-42gx-v2fc-7h6fBDU:2019-03248VVD-MAGEIA-2019-172CVE-2018-1000026GHSA-28gp-589x-6r7fBDU:2020-00842EUVD-2019-13442EUVD-2018-10126GHSA-7qc9-w55v-w7p3GHSA-c7q5-cw8v-48xhGHSA-794c-rcrg-7j7wCVE-2018-18397BDU:2019-02688VVD-MAGEIA-2019-98EUVD-2018-1787BDU:2020-00620GHSA-fq7v-x63h-q5h9EUVD-2019-3159VVD-MAGEIA-2019-171CVE-2019-3701VVD-MAGEIA-2019-97BDU:2019-02782EUVD-2018-11499EUVD-2018-11652CVE-2019-3819EUVD-2019-13336GHSA-pv82-pww5-29fvEUVD-2018-11772GHSA-7cx6-7887-9rwv
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.