VDB
GCVE-VVD-MAGEIA-2019-221
GCVE-VVD-MAGEIA-2019-221
Advisory Published
This kernel update is based on the upstream 4.14.137 and fixes at least
the following security issues:
A Spectre SWAPGS gadget was found in the Linux kernel's implementation of
system interrupts. An attacker with local access could use this information
to reveal private data through a Spectre like side channel (CVE-2019-1125).
A flaw that allowed an attacker to corrupt memory and possibly escalate
privileges was found in the mwifiex kernel module while connecting to a
malicious wireless network (CVE-2019-3846).
An infinite loop issue was found in the vhost_net kernel module in Linux
Kernel up to and including v5.1-rc6, while handling incoming packets in
handle_rx(). It could occur if one end sends packets faster than the other
end can process them. A guest user, maybe remote one, could use this flaw
to stall the vhost_net kernel thread, resulting in a DoS scenario
(CVE-2019-3900).
A flaw was found in the Linux kernel’s Bluetooth implementation of UART.
An attacker with local access and write permissions to the Bluetooth
hardware could use this flaw to issue a specially crafted ioctl function
call and cause the system to crash (CVE-2019-10207).
WireGuard has been updated to 0.0.20190702.
For other uptstream fixes in this update, see the referenced changelogs.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | kernel-userspace-headers | 0 (affected), 4.14.137-1.mga6 (unaffected), 0 (affected), 4.14.137-1.mga6 (unaffected) | — |
| Mageia | kernel | 0 (affected), 4.14.137-1.mga6 (unaffected), 0 (affected), 4.14.137-1.mga6 (unaffected) | — |
| Mageia | plasma-workspace | 0 (affected), 5.15.4-1.1.mga7 (unaffected) | — |
| Mageia | kmod-virtualbox | 0 (affected), 6.0.10-2.mga6 (unaffected), 0 (affected), 6.0.10-2.mga6 (unaffected) | — |
| Mageia | wireguard-tools | 0 (affected), 0.0.20190702-1.mga6 (unaffected), 0 (affected), 0.0.20190702-1.mga6 (unaffected) | — |
| Mageia | kmod-xtables-addons | 0 (affected), 2.13-90.mga6 (unaffected), 0 (affected), 2.13-90.mga6 (unaffected) | — |
| Mageia | kmod-vboxadditions | 0 (affected), 6.0.10-2.mga6 (unaffected), 0 (affected), 6.0.10-2.mga6 (unaffected) | — |
Aliases
Transitive aliases
GHSA-8885-wr7g-q9vxCVE-2019-14814BDU:2019-02927VVD-MAGEIA-2019-288EUVD-2019-5943GHSA-5prc-226w-5qr4VVD-CERTFI-2019-0012BDU:2019-03812GSD-2020-9395CVE-2019-14816CVE-2019-17666EUVD-2019-5944BDU:2019-04533CVE-2020-9395EUVD-2020-30216GHSA-m35f-qmp6-pvj2CNVD-2021-18235CVE-2019-14815GHSA-frg3-qcjh-fvr9GHSA-3fcq-fcfj-jgfqCNVD-2019-38261GHSA-wcxr-pc79-vh4xCVE-2019-16714BDU:2020-03327VAR-202007-1257VVD-MAGEIA-2019-220EUVD-2019-2224CVE-2019-0155VVD-MAGEIA-2019-287GSD-2019-16714GHSA-qw7j-pqgw-px85EUVD-2019-7971VVD-MAGEIA-2019-333GHSA-pg5g-xqv8-wqm8EUVD-2019-7264OPENSUSE-SU-2024:10895-1VVD-MAGEIA-2019-306VVD-MAGEIA-2019-332BDU:2019-04744EUVD-2019-13466BDU:2020-03328EUVD-2019-5945EUVD-2019-0962BDU:2020-03329GHSA-pv85-r7p2-8r62
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.