AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-14835

HIGH · CVSS 7.8 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-09-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-14835
Severity
HIGH
CVSS
7.8
EPSS
0.63%
Linux

Original NVD Description

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.