CVE-2019-11135

medium
Published 2020-01-29 Β· Modified 2020-02-04
CVSS v3
6.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
6.5

Description

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

Predictions

Exploit likelihood
65%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description hw: TSX Transaction Asynchronous Abort (TAA) Red Hat statement libvirt and qemu-kvm on Red Hat Enterprise Linux 6 are not affected by this vulnerability as they do not support MSR-based CPU features. CVSS v3: 6.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Advanced Virtualization for RHEL…

Description

hw: TSX Transaction Asynchronous Abort (TAA)

Red Hat statement

libvirt and qemu-kvm on Red Hat Enterprise Linux 6 are not affected by this vulnerability as they do not support MSR-based CPU features.

CVSS v3: 6.5 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Advanced Virtualization for RHEL 8.1.0virt:8.1-8010020191227172441.c27ad7f8RHSA-2020:05552020-02-19T00:00:00Z
Advanced Virtualization for RHEL 8.1.0virt-devel:8.1-8010020191227172441.c27ad7f8RHSA-2020:05552020-02-19T00:00:00Z
Red Hat Enterprise Linux 6kernel-0:2.6.32-754.24.2.el6RHSA-2019:38362019-11-12T00:00:00Z
Red Hat Enterprise Linux 6.5 Advanced Update Supportkernel-0:2.6.32-431.96.3.el6RHSA-2019:38432019-11-12T00:00:00Z
Red Hat Enterprise Linux 6.6 Advanced Update Supportkernel-0:2.6.32-504.81.3.el6RHSA-2019:38422019-11-12T00:00:00Z
Red Hat Enterprise Linux 7kernel-rt-0:3.10.0-1062.4.2.rt56.1028.el7RHSA-2019:38352019-11-12T00:00:00Z
Red Hat Enterprise Linux 7kernel-0:3.10.0-1062.4.2.el7RHSA-2019:38342019-11-12T00:00:00Z
Red Hat Enterprise Linux 7kpatch-patchRHSA-2020:00282020-01-06T00:00:00Z
Red Hat Enterprise Linux 7qemu-kvm-10:1.5.3-167.el7_7.4RHSA-2020:03662020-02-04T00:00:00Z
Red Hat Enterprise Linux 7.2 Advanced Update Supportkernel-0:3.10.0-327.82.2.el7RHSA-2019:38412019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.2 Telco Extended Update Supportkernel-0:3.10.0-327.82.2.el7RHSA-2019:38412019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutionskernel-0:3.10.0-327.82.2.el7RHSA-2019:38412019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.3 Advanced Update Supportkernel-0:3.10.0-514.70.2.el7RHSA-2019:38402019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.3 Telco Extended Update Supportkernel-0:3.10.0-514.70.2.el7RHSA-2019:38402019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutionskernel-0:3.10.0-514.70.2.el7RHSA-2019:38402019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.4 Advanced Update Supportkernel-0:3.10.0-693.60.2.el7RHSA-2019:38392019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.4 Telco Extended Update Supportkernel-0:3.10.0-693.60.2.el7RHSA-2019:38392019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutionskernel-0:3.10.0-693.60.2.el7RHSA-2019:38392019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.5 Extended Update Supportkernel-0:3.10.0-862.43.2.el7RHSA-2019:38382019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.6 Extended Update Supportkernel-0:3.10.0-957.38.2.el7RHSA-2019:38372019-11-12T00:00:00Z
Red Hat Enterprise Linux 7.6 Extended Update Supportkpatch-patchRHSA-2020:00262020-01-06T00:00:00Z
Red Hat Enterprise Linux 7.6 Extended Update Supportqemu-kvm-10:1.5.3-160.el7_6.5RHSA-2020:06662020-03-03T00:00:00Z
Red Hat Enterprise Linux 8virt-devel:rhel-8010020191216093608.c27ad7f8RHSA-2020:02792020-01-29T00:00:00Z
Red Hat Enterprise Linux 8virt:rhel-8010020191216093608.c27ad7f8RHSA-2020:02792020-01-29T00:00:00Z
Red Hat Enterprise Linux 8kernel-rt-0:4.18.0-147.0.2.rt24.94.el8_1RHSA-2019:38332019-11-12T00:00:00Z
Red Hat Enterprise Linux 8kernel-0:4.18.0-147.0.2.el8_1RHSA-2019:38322019-11-12T00:00:00Z
Red Hat Enterprise Linux 8kpatch-patchRHSA-2019:39362019-11-22T00:00:00Z
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionskernel-0:4.18.0-80.15.1.el8_0RHSA-2020:02042020-01-22T00:00:00Z
Red Hat Enterprise MRG 2kernel-rt-1:3.10.0-693.60.2.rt56.655.el6rtRHSA-2019:38442019-11-12T00:00:00Z
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSkernel-0:3.10.0-957.38.2.el7RHSA-2019:38372019-11-12T00:00:00Z
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSredhat-virtualization-host-0:4.2-20191107.0.el7_6RHSA-2019:38602019-11-12T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-virtualization-host-0:4.3.6-20191108.0.el7_7RHSA-2019:38602019-11-12T00:00:00Z
Red Hat Virtualization Engine 4.2qemu-kvm-rhev-10:2.12.0-18.el7_6.9RHSA-2020:07302020-03-05T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 5kernelOut of support scope
Red Hat Enterprise Linux 5microcode_ctlOut of support scope
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 6microcode_ctlAffected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7libvirtAffected
Red Hat Enterprise Linux 7microcode_ctlAffected
Red Hat Enterprise Linux 7qemu-kvm-rhevAffected
Red Hat Enterprise Linux 8microcode_ctlAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationqemu-kvmAffected

Apply commands

bash fix
Apply RHSA-2020:0555 for Advanced Virtualization for RHEL 8.1.0
yum update -y virt:8
# or:
dnf upgrade -y virt:8

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8 Advanced VirtualizationAffected

OS impact

fedora Fedora Affected 2 releases
VersionStatusFixed in
31 Affected β€”
30 Affected β€”
suse SUSE Affected 3 releases
VersionStatusFixed in
15.1 Affected β€”
15.0 Affected β€”
β€” Affected β€”
ubuntu Ubuntu Affected 1 release
VersionStatusFixed in
14.04 Affected β€”
debian Debian Mixed 8 releases
VersionStatusFixed in
trixie Fixed 3.20191112.1
sid Fixed 3.20191112.1
forky Fixed 3.20191112.1
bullseye Fixed 3.20191112.1
bookworm Fixed 3.20191112.1
10.0 Affected β€”
9.0 Affected β€”
8.0 Affected β€”
redhat Red Hat Mixed 9 releases
VersionStatusFixed in
8.6 Affected β€”
8.4 Affected β€”
8.2 Affected β€”
8.1 Affected β€”
8.0 Affected β€”
8 Fixed β€”
7.7 Affected β€”
7.6 Affected β€”
7.0 Affected β€”
arch Arch Fixed 1 release
VersionStatusFixed in
β€” Fixed 20191112-1
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

Application impact

VendorProductVersionsFixed
slackwareslackware14.2
hp hpapollo_4200gen10
hp hpapollo_2000-
hp hpproliant_bl460cgen10
hp hpproliant_dl580gen10
hp hpproliant_dl560gen10
hp hpproliant_dl380gen10
hp hpproliant_dl360gen10
hp hpproliant_dl180gen10
hp hpproliant_dl160gen10
hp hpproliant_dl120gen10
hp hpproliant_dl20gen10
hp hpproliant_ml350gen10
hp hpproliant_ml110gen10
hp hpproliant_ml30gen10
hp hpproliant_xl450gen10
hp hpproliant_xl270dgen10
hp hpproliant_xl230kgen10
hp hpproliant_xl190rgen10
hp hpproliant_xl170rgen10
hp hpsynergy_480gen10
hp hpsynergy_660gen10
hp hpproliant_e910-
intel intelcore_i7-10510y-
intel intelcore_i5-10310y-
intel intelcore_i5-10210y-
intel intelcore_i5-10110y-
intel intelcore_i7-8500y-
intel intelcore_i5-8310y-
intel intelcore_i5-8210y-
intel intelcore_i5-8200y-
intel intelcore_m3-8100y-
intel intelxeon_8253-
intel intelxeon_8256-
intel intelxeon_8260-
intel intelxeon_8260l-
intel intelxeon_8260m-
intel intelxeon_8260y-
intel intelxeon_8268-
intel intelxeon_8270-
intel intelxeon_8276-
intel intelxeon_8276l-
intel intelxeon_8276m-
intel intelxeon_8280-
intel intelxeon_8280l-
intel intelxeon_8280m-
intel intelxeon_9220-
intel intelxeon_9221-
intel intelxeon_9222-
intel intelxeon_9242-
intel intelxeon_9282-
intel intelxeon_5215-
intel intelxeon_5215l-
intel intelxeon_5215m-
intel intelxeon_5215r-
intel intelxeon_5217-
intel intelxeon_5218-
intel intelxeon_5218b-
intel intelxeon_5218n-
intel intelxeon_5218t-
intel intelxeon_5220-
intel intelxeon_5220r-
intel intelxeon_5220s-
intel intelxeon_5220t-
intel intelxeon_5222-
intel intelxeon_6222v-
intel intelxeon_6226-
intel intelxeon_6230-
intel intelxeon_6230n-
intel intelxeon_6230t-
intel intelxeon_6234-
intel intelxeon_6238-
intel intelxeon_6238l-
intel intelxeon_6238m-
intel intelxeon_6238t-
intel intelxeon_6240-
intel intelxeon_6240l-
intel intelxeon_6240m-
intel intelxeon_6240y-
intel intelxeon_6242-
intel intelxeon_6244-
intel intelxeon_6246-
intel intelxeon_6248-
intel intelxeon_6252-
intel intelxeon_6252n-
intel intelxeon_6254-
intel intelxeon_6262v-
intel intelxeon_4208-
intel intelxeon_4208r-
intel intelxeon_4209t-
intel intelxeon_4210-
intel intelxeon_4210r-
intel intelxeon_4214-
intel intelxeon_4214c-
intel intelxeon_4214r-
intel intelxeon_4214y-
intel intelxeon_4215-
intel intelxeon_4216-
intel intelxeon_4216r-
intel intelxeon_3204-
intel intelxeon_3206r-
intel intelxeon_w-3275m-
intel intelxeon_w-3275-
intel intelxeon_w-3265m-
intel intelxeon_w-3265-
intel intelxeon_w-3245m-
intel intelxeon_w-3245-
intel intelxeon_w-3235-
intel intelxeon_w-3225-
intel intelxeon_w-3223-
intel intelxeon_w-2295-
intel intelxeon_w-2275-
intel intelxeon_w-2265-
intel intelxeon_w-2255-
intel intelxeon_w-2245-
intel intelxeon_w-2235-
intel intelxeon_w-2225-
intel intelxeon_w-2223-
intel intelcore_i9-9980hk-
intel intelcore_i9-9880h-
intel intelcore_i7-9850h-
intel intelcore_i7-9750hf-
intel intelcore_i5-9400h-
intel intelcore_i5-9300h-
intel intelcore_i9-9900k-
intel intelcore_i9-9900kf-
intel intelcore_i7-9700k-
intel intelcore_i7-9700kf-
intel intelcore_i5-9600k-
intel intelcore_i5-9600kf-
intel intelcore_i5-9400-
intel intelcore_i5-9400f-
intel intelxeon_e-2288g-
intel intelxeon_e-2286m-
intel intelxeon_e-2278gel-
intel intelxeon_e-2278ge-
intel intelxeon_e-2278g-
intel intelcore_i7-10510u-
intel intelcore_i5-10210u-
intel intelpentium_6405u-
intel intelceleron_5305u-
intel intelcore_i7-8565u-
intel intelcore_i7-8665u-
intel intelcore_i5-8365u-
intel intelcore_i5-8265u-
redhat redhatcodeready_linux_builder8.0
redhat redhatcodeready_linux_builder_eus8.1
redhat redhatcodeready_linux_builder_eus8.2
redhat redhatcodeready_linux_builder_eus8.4
redhat redhatcodeready_linux_builder_eus8.6
redhat redhatvirtualization_manager4.2
oracle oraclezfs_storage_appliance_kit8.8
intel intelcore_i7-10510y_firmware-
intel intelcore_i5-10310y_firmware-
intel intelcore_i5-10210y_firmware-
intel intelcore_i5-10110y_firmware-
intel intelcore_i7-8500y_firmware-
intel intelcore_i5-8310y_firmware-
intel intelcore_i5-8210y_firmware-
intel intelcore_i5-8200y_firmware-
intel intelcore_m3-8100y_firmware-
intel intelxeon_8253_firmware-
intel intelxeon_8256_firmware-
intel intelxeon_8260_firmware-
intel intelxeon_8260l_firmware-
intel intelxeon_8260m_firmware-
intel intelxeon_8260y_firmware-
intel intelxeon_8268_firmware-
intel intelxeon_8270_firmware-
intel intelxeon_8276_firmware-
intel intelxeon_8276l_firmware-
intel intelxeon_8276m_firmware-
intel intelxeon_8280_firmware-
intel intelxeon_8280l_firmware-
intel intelxeon_8280m_firmware-
intel intelxeon_9220_firmware-
intel intelxeon_9221_firmware-
intel intelxeon_9222_firmware-
intel intelxeon_9242_firmware-
intel intelxeon_9282_firmware-
intel intelxeon_5215_firmware-
intel intelxeon_5215l_firmware-
intel intelxeon_5215m_firmware-
intel intelxeon_5215r_firmware-
intel intelxeon_5217_firmware-
intel intelxeon_5218_firmware-
intel intelxeon_5218b_firmware-
intel intelxeon_5218n_firmware-
intel intelxeon_5218t_firmware-
intel intelxeon_5220_firmware-
intel intelxeon_5220r_firmware-
intel intelxeon_5220s_firmware-
intel intelxeon_5220t_firmware-
intel intelxeon_5222_firmware-
intel intelxeon_6222v_firmware-
intel intelxeon_6226_firmware-
intel intelxeon_6230_firmware-
intel intelxeon_6230n_firmware-
intel intelxeon_6230t_firmware-
intel intelxeon_6234_firmware-

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.