{"id":"CVE-2019-7221","details":"The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.","modified":"2026-04-16T01:39:28.076494035Z","published":"2019-03-21T16:01:10.890Z","related":["SUSE-SU-2019:0541-1","SUSE-SU-2019:0645-1","SUSE-SU-2019:0672-1","SUSE-SU-2019:0683-1","SUSE-SU-2019:0709-1","SUSE-SU-2019:0722-1","SUSE-SU-2019:0726-1","SUSE-SU-2019:0740-1","SUSE-SU-2019:0745-1","SUSE-SU-2019:0754-1","SUSE-SU-2019:0765-1","SUSE-SU-2019:0767-1","SUSE-SU-2019:0784-1","SUSE-SU-2019:0785-1","SUSE-SU-2019:0828-1","SUSE-SU-2019:0845-1","SUSE-SU-2019:0901-1","SUSE-SU-2019:1289-1","openSUSE-SU-2019:0203-1","openSUSE-SU-2024:10728-1","openSUSE-SU-2024:13704-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_FIELD","extracted_events":[{"last_affected":"14.04"}],"cpe":"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"16.04"}],"cpe":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"18.04"}],"cpe":"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"18.10"}],"cpe":"cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"8.0"}],"cpe":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"28"}],"cpe":"cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"29"}],"cpe":"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.20.5"}],"cpe":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"15.0"}],"cpe":"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.0"}],"cpe":"cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.0"}],"cpe":"cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.0"}],"cpe":"cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.6"}],"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.6"}],"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.6"}],"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"7.0"}],"cpe":"cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KDOXCX3QFVWYXH5CQMGDDE7H6MUG5XGG/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y2HMABEMJDPA6LPCBE5WIEZXUKY7DLTN/"},{"type":"WEB","url":"https://support.f5.com/csp/article/K08413011"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00042.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/151713/KVM-VMX-Preemption-Timer-Use-After-Free.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2019:0959"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:0818"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:0833"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3967"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4058"},{"type":"ADVISORY","url":"https://github.com/torvalds/linux/commits/master/arch/x86/kvm"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190404-0002/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3930-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3930-2/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3931-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3931-2/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3932-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3932-2/"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2019/02/18/2"},{"type":"FIX","url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1760"},{"type":"FIX","url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ecec76885bcfe3294685dc363fd1273df0d5d65f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/torvalds/linux","events":[{"introduced":"0"},{"last_affected":"6e4664525b1db28f8c4e1130957f70a94c19213e"}],"database_specific":{"source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"3.11"}],"cpe":"cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*"}}],"versions":["v2.6.12-rc2","v2.6.12-rc3","v2.6.12-rc4","v2.6.13","v2.6.13-rc1","v2.6.13-rc2","v2.6.13-rc3","v2.6.13-rc4","v2.6.13-rc5","v2.6.13-rc6","v2.6.13-rc7","v2.6.14-rc1","v2.6.14-rc2","v2.6.14-rc3","v2.6.15-rc1","v2.6.15-rc2","v2.6.15-rc4","v2.6.15-rc5","v2.6.15-rc7","v2.6.16","v2.6.16-rc1","v2.6.16-rc2","v2.6.16-rc3","v2.6.16-rc4","v2.6.16-rc5","v2.6.16-rc6","v2.6.17","v2.6.17-rc1","v2.6.17-rc2","v2.6.17-rc3","v2.6.17-rc4","v2.6.17-rc5","v2.6.17-rc6","v2.6.18","v2.6.18-rc1","v2.6.18-rc2","v2.6.18-rc3","v2.6.18-rc5","v2.6.18-rc6","v2.6.19-rc1","v2.6.19-rc2","v2.6.20-rc1","v2.6.20-rc2","v2.6.20-rc3","v2.6.20-rc4","v2.6.20-rc5","v2.6.20-rc6","v2.6.20-rc7","v2.6.21","v2.6.21-rc1","v2.6.21-rc2","v2.6.21-rc3","v2.6.21-rc4","v2.6.21-rc5","v2.6.21-rc6","v2.6.21-rc7","v2.6.22","v2.6.22-rc1","v2.6.22-rc2","v2.6.22-rc3","v2.6.22-rc4","v2.6.22-rc5","v2.6.22-rc6","v2.6.22-rc7","v2.6.23","v2.6.23-rc1","v2.6.23-rc2","v2.6.23-rc3","v2.6.23-rc4","v2.6.23-rc5","v2.6.23-rc6","v2.6.23-rc7","v2.6.23-rc8","v2.6.23-rc9","v2.6.24","v2.6.24-rc1","v2.6.24-rc2","v2.6.24-rc3","v2.6.24-rc4","v2.6.24-rc5","v2.6.24-rc6","v2.6.24-rc7","v2.6.24-rc8","v2.6.25","v2.6.25-rc1","v2.6.25-rc2","v2.6.25-rc3","v2.6.25-rc4","v2.6.25-rc5","v2.6.25-rc6","v2.6.25-rc7","v2.6.25-rc8","v2.6.25-rc9","v2.6.26","v2.6.26-rc1","v2.6.26-rc2","v2.6.26-rc3","v2.6.26-rc4","v2.6.26-rc5","v2.6.26-rc6","v2.6.26-rc7","v2.6.26-rc8","v2.6.26-rc9","v2.6.27","v2.6.27-rc1","v2.6.27-rc2","v2.6.27-rc3","v2.6.27-rc4","v2.6.27-rc5","v2.6.27-rc6","v2.6.27-rc7","v2.6.27-rc8","v2.6.27-rc9","v2.6.28","v2.6.28-rc1","v2.6.28-rc2","v2.6.28-rc3","v2.6.28-rc4","v2.6.28-rc5","v2.6.28-rc6","v2.6.28-rc7","v2.6.28-rc8","v2.6.28-rc9","v2.6.29","v2.6.29-rc1","v2.6.29-rc2","v2.6.29-rc3","v2.6.29-rc4","v2.6.29-rc5","v2.6.29-rc6","v2.6.29-rc7","v2.6.29-rc8","v2.6.30","v2.6.30-rc1","v2.6.30-rc2","v2.6.30-rc3","v2.6.30-rc4","v2.6.30-rc5","v2.6.30-rc6","v2.6.30-rc7","v2.6.30-rc8","v2.6.31","v2.6.31-rc1","v2.6.31-rc2","v2.6.31-rc3","v2.6.31-rc4","v2.6.31-rc5","v2.6.31-rc6","v2.6.31-rc7","v2.6.31-rc8","v2.6.31-rc9","v2.6.32","v2.6.32-rc1","v2.6.32-rc2","v2.6.32-rc3","v2.6.32-rc4","v2.6.32-rc5","v2.6.32-rc6","v2.6.32-rc7","v2.6.32-rc8","v2.6.33","v2.6.33-rc1","v2.6.33-rc2","v2.6.33-rc3","v2.6.33-rc4","v2.6.33-rc5","v2.6.33-rc6","v2.6.33-rc7","v2.6.33-rc8","v2.6.34","v2.6.34-rc1","v2.6.34-rc2","v2.6.34-rc3","v2.6.34-rc4","v2.6.34-rc5","v2.6.34-rc6","v2.6.34-rc7","v2.6.35","v2.6.35-rc1","v2.6.35-rc2","v2.6.35-rc3","v2.6.35-rc4","v2.6.35-rc5","v2.6.35-rc6","v2.6.36","v2.6.36-rc1","v2.6.36-rc2","v2.6.36-rc3","v2.6.36-rc4","v2.6.36-rc5","v2.6.36-rc6","v2.6.36-rc7","v2.6.36-rc8","v2.6.37","v2.6.37-rc1","v2.6.37-rc2","v2.6.37-rc3","v2.6.37-rc4","v2.6.37-rc5","v2.6.37-rc6","v2.6.37-rc7","v2.6.37-rc8","v2.6.38","v2.6.38-rc1","v2.6.38-rc2","v2.6.38-rc3","v2.6.38-rc4","v2.6.38-rc5","v2.6.38-rc6","v2.6.38-rc7","v2.6.38-rc8","v2.6.39","v2.6.39-rc1","v2.6.39-rc2","v2.6.39-rc3","v2.6.39-rc4","v2.6.39-rc5","v2.6.39-rc6","v2.6.39-rc7","v3.0","v3.0-rc1","v3.0-rc2","v3.0-rc3","v3.0-rc4","v3.0-rc5","v3.0-rc6","v3.0-rc7","v3.1","v3.1-rc1","v3.1-rc10","v3.1-rc2","v3.1-rc3","v3.1-rc4","v3.1-rc5","v3.1-rc6","v3.1-rc7","v3.1-rc8","v3.1-rc9","v3.10","v3.10-rc1","v3.10-rc2","v3.10-rc3","v3.10-rc4","v3.10-rc5","v3.10-rc6","v3.10-rc7","v3.11","v3.11-rc1","v3.11-rc2","v3.11-rc3","v3.11-rc4","v3.11-rc5","v3.11-rc6","v3.11-rc7","v3.2","v3.2-rc1","v3.2-rc2","v3.2-rc3","v3.2-rc4","v3.2-rc5","v3.2-rc6","v3.2-rc7","v3.3","v3.3-rc1","v3.3-rc2","v3.3-rc3","v3.3-rc4","v3.3-rc5","v3.3-rc6","v3.3-rc7","v3.4","v3.4-rc1","v3.4-rc2","v3.4-rc3","v3.4-rc4","v3.4-rc5","v3.4-rc6","v3.4-rc7","v3.5","v3.5-rc1","v3.5-rc2","v3.5-rc3","v3.5-rc4","v3.5-rc5","v3.5-rc6","v3.5-rc7","v3.6","v3.6-rc1","v3.6-rc2","v3.6-rc3","v3.6-rc4","v3.6-rc5","v3.6-rc6","v3.6-rc7","v3.7","v3.7-rc1","v3.7-rc2","v3.7-rc3","v3.7-rc4","v3.7-rc5","v3.7-rc6","v3.7-rc7","v3.7-rc8","v3.8","v3.8-rc1","v3.8-rc2","v3.8-rc3","v3.8-rc4","v3.8-rc5","v3.8-rc6","v3.8-rc7","v3.9","v3.9-rc1","v3.9-rc2","v3.9-rc3","v3.9-rc4","v3.9-rc5","v3.9-rc6","v3.9-rc7","v3.9-rc8"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-7221.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}