Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-14821

28
FAUCET Score

CVE-2019-14821 is an out-of-bounds access vulnerability in the Linux kernel's KVM hypervisor, affecting all versions through 5.3, including distributions like Red Hat, Debian, and Ubuntu. An unprivileged host user with /dev/kvm access can exploit this flaw by manipulating MMIO ring buffer indices, leading to a host kernel crash (Denial of Service) or potential privilege escalation. With a CVSS score of 8.8 (High), this vulnerability has a low attack complexity and requires local access. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.27, <= 3.15.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.16, < 3.16.74CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.4, < 4.4.194CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.9, < 4.9.194CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.14, < 4.14.146CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.1
Impact Score
5.8
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.76%
Probability of exploitation in next 30 days
EPSS Percentile
51.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0076 is in the 88th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-754.25.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-1062.7.1.rt56.1030.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-1062.7.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt-0:4.14.0-115.16.1.el7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: kernel-0:3.10.0-957.56.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-147.rt24.93.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-147.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-80.15.1.el8_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSFixed in: kernel-0:3.10.0-957.56.1.el7
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt

Vendor Advisories (1)

redhatCVE-2019-14821Important

Kernel: KVM: OOB memory access via mmio ring buffer

Sep 17, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-10/msg00036.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-10/msg00037.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:3309
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3517
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3978
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3979
Third Party Advisory
access.redhat.com / errata/RHSA-2019:4154
Third Party Advisory
access.redhat.com / errata/RHSA-2019:4256
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0027
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0204
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingMitigationPatchThird Party Advisory
lists.debian.org / debian-lts-announce/2019/09/msg00025.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2019/10/msg00000.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TRZQQQANZWQMPILZV7OTS3RGGRLLE2Q7
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YW3QNMPENPFEGVTOFPSNOBL7JEIJS25P
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Nov/11
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Sep/41
Issue TrackingMailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20191004-0001
Third Party Advisory
usn.ubuntu.com / 4157-1
Third Party Advisory
usn.ubuntu.com / 4157-2
Third Party Advisory
usn.ubuntu.com / 4162-1
Third Party Advisory
usn.ubuntu.com / 4162-2
Third Party Advisory
usn.ubuntu.com / 4163-1
Third Party Advisory
usn.ubuntu.com / 4163-2
Third Party Advisory
debian.org / security/2019/dsa-4531
Third Party Advisory
oracle.com / security-alerts/cpuapr2020.html
Third Party Advisory
openwall.com / lists/oss-security/2019/09/20/1
Mailing ListPatchThird Party Advisory