Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-11135

26
FAUCET Score

CVE-2019-11135 is a medium-severity information disclosure vulnerability affecting various Intel CPUs and related products from vendors like Canonical, Debian, and Red Hat. It stems from a TSX Asynchronous Abort condition that, under specific speculative execution scenarios, allows an authenticated local user to potentially extract sensitive information via a side-channel attack. The attack requires local access and has low complexity, but the impact is limited to confidentiality. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
15.0CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
15.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
14.2CPE matchmatch criteria
cpe:2.3:a:slackware:slackware:14.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.0
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.13%
Probability of exploitation in next 30 days
EPSS Percentile
86.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0313 is in the 99th percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (88)

amazonpatch availablevia llm_extracted
View patch
cephpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
denopatch availablevia llm_extracted
View patch
dotnetpatch availablevia llm_extracted
View patch
firefoxpatch availablevia llm_extracted
View patch
fleetdmpatch availablevia llm_extracted
View patch
invoiceplanepatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1803 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1803 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows Server, version 1803 (Server Core Installation)
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1803 for ARM64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for ARM64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1709 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1709 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1709 for ARM64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1903 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1903 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1903 for ARM64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows Server, version 1903 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows 10 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1607 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1607 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows 7 for 32-bit Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Windows 7 for x64-based Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Windows 8.1 for 32-bit systems
View patch
microsoftpatch availablevia msrc
Product: Windows 8.1 for x64-based systems
View patch
microsoftpatch availablevia msrc
Product: Windows RT 8.1
microsoftpatch availablevia msrc
Product: Windows Server 2008 for 32-bit Systems Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for Itanium-Based Systems Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for x64-based Systems Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for x64-based Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2 (Server Core installation)
View patch
oraclepatch availablevia nvd_reference
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Advanced Update SupportFixed in: kernel-0:2.6.32-504.81.3.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm-10:1.5.3-167.el7_7.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Advanced Update SupportFixed in: kernel-0:3.10.0-327.82.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Telco Extended Update SupportFixed in: kernel-0:3.10.0-327.82.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-327.82.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: kernel-0:3.10.0-514.70.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Telco Extended Update SupportFixed in: kernel-0:3.10.0-514.70.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-514.70.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: kernel-0:3.10.0-693.60.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: kernel-0:3.10.0-693.60.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-693.60.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.5 Extended Update SupportFixed in: kernel-0:3.10.0-862.43.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: kernel-0:3.10.0-957.38.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: qemu-kvm-10:1.5.3-160.el7_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: virt-devel:rhel-8010020191216093608.c27ad7f8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: virt:rhel-8010020191216093608.c27ad7f8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-147.0.2.rt24.94.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-147.0.2.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-80.15.1.el8_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.60.2.rt56.655.el6rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSFixed in: kernel-0:3.10.0-957.38.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSFixed in: redhat-virtualization-host-0:4.2-20191107.0.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: redhat-virtualization-host-0:4.3.6-20191108.0.el7_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.2Fixed in: qemu-kvm-rhev-10:2.12.0-18.el7_6.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-1062.4.2.rt56.1028.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Advanced Update SupportFixed in: kernel-0:2.6.32-431.96.3.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-754.24.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Advanced Virtualization for RHEL 8.1.0Fixed in: virt:8.1-8010020191227172441.c27ad7f8
View patch
redhatpatch availablevia redhat_api
Product: Advanced Virtualization for RHEL 8.1.0Fixed in: virt-devel:8.1-8010020191227172441.c27ad7f8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-1062.4.2.el7
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libvirt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: microcode_ctl
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8 Advanced VirtualizationFixed in: qemu-kvm
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: microcode_ctl
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: microcode_ctl

Vendor Advisories (23)

redhatCVE-2019-11135Moderate

hw: TSX Transaction Asynchronous Abort (TAA)

Nov 12, 2019
microsoft2019-Nov/CVE-2019-11135Important

Windows Kernel Information Disclosure Vulnerability

Nov 12, 2019
pjsipllm-pjsip-a1583ac1d0cdf561MEDIUM

Intel TSX Async Abort (TAA) and Machine Check Error on Page Size Change

Jan 1, 2019
cephllm-ceph-ceb90cada80506d3

Google Kubernetes Engine - CVE-2019-11135

cephllm-ceph-2a53eb470427ec5b

App Engine flexible environment - CVE-2019-11135

cephllm-ceph-c9eeea08f9717e84

Dataflow - CVE-2019-11135

cephllm-ceph-47946ff083eea29f

Dataproc - CVE-2019-11135

firefoxllm-firefox-6b1a3b2b6ef4ee11

Google Kubernetes Engine Security Advisory for CVE-2019-11135

firefoxllm-firefox-8ea32fbee68f2ee6

App Engine flexible environment Security Advisory for CVE-2019-11135

firefoxllm-firefox-cea40e3282231417

Dataflow Security Advisory for CVE-2019-11135

firefoxllm-firefox-1d3f871bff7d549f

Dataproc Security Advisory for CVE-2019-11135

amazonllm-amazon-d00dbb717d4e9994

Google Kubernetes Engine Security Advisory for CVE-2019-11135

amazonllm-amazon-775ba839b135ab34

App Engine flexible environment Security Advisory for CVE-2019-11135

amazonllm-amazon-94bacc9bf9849174

Dataflow Security Advisory for CVE-2019-11135

amazonllm-amazon-5c908c19d122902c

Dataproc Security Advisory for CVE-2019-11135

fleetdmllm-fleetdm-7a0b7b96b8d71973

Google Kubernetes Engine - CVE-2019-11135

fleetdmllm-fleetdm-2bb6e12b83a47527

App Engine flexible environment - CVE-2019-11135

fleetdmllm-fleetdm-f7a3095d1832de3a

Dataflow - CVE-2019-11135

fleetdmllm-fleetdm-cf89ec6abff3e1cf

Dataproc - CVE-2019-11135

chromellm-chrome-387a12d881d136e7

Google Kubernetes Engine - CVE-2019-11135

dotnetllm-dotnet-df406c6cea05a71a

Security Advisory for Google Kubernetes Engine

invoiceplanellm-invoiceplane-d2f25874b23ee2c4MEDIUM

This vulnerability referred to as TSX Async Abort (TAA) can be used to exploit speculative execution within a TSX transaction. This vulnerability potentially allows data to be exposed via the same microarchitectural data structures exposed by Microarchitectural Data Sampling (MDS).

denollm-deno-f8f381813ecf5c79MEDIUM

TSX Async Abort (TAA) Vulnerability

References

lists.opensuse.org / opensuse-security-announce/2019-11/msg00045.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-11/msg00046.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-12/msg00042.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/155375/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
PatchThird Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:3936
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0026
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0028
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0204
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0279
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0366
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0555
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0666
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0730
Third Party Advisory
kc.mcafee.com / corporate/index
Third Party Advisory
lists.debian.org / debian-lts-announce/2019/12/msg00035.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/I5WWPW4BSZDDW7VHU427XTVXV7ROOFFW
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/IZYATWNUGHRBG6I3TC24YHP5Y3J7I6KH
seclists.org / bugtraq/2019/Dec/28
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Nov/26
Mailing ListPatchThird Party Advisory
seclists.org / bugtraq/2020/Jan/21
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202003-56
Third Party Advisory
support.f5.com / csp/article/K02912734
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
usn.ubuntu.com / 4186-2
Third Party Advisory
debian.org / security/2020/dsa-4602
Third Party Advisory
intel.com / content/www/us/en/security-center/advisory/intel-sa-00270.html
Vendor Advisory
oracle.com / security-alerts/cpujan2021.html
PatchThird Party Advisory
openwall.com / lists/oss-security/2019/12/10/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/12/10/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/12/11/1
Mailing ListThird Party Advisory