Back
CVE-2019-14901
CRITICAL
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.
Published: Nov 29, 2019
Modified: Jun 17, 2026
CWE-122
CWE-400
CWE-787
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (13)
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | * ≥ 3.15 < 3.16.83 |
| linux | linux_kernel | * ≥ 3.17 < 4.4.217 |
| linux | linux_kernel | * ≥ 4.5 < 4.9.217 |
| linux | linux_kernel | * ≥ 4.10 < 4.14.164 |
| linux | linux_kernel | * ≥ 4.15 < 4.19.95 |
| linux | linux_kernel | * ≥ 4.20 < 5.4.11 |
| fedoraproject | fedora | 30 |
| fedoraproject | fedora | 31 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.10 |
GitHub Security Advisory GHSA-6mpr-24px-gq7m
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0,...
References (40)
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/155879/Kernel-Live-Patch-Security-Notice-LSN-0061-1.html Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.html Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2020:0204 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0328 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0339 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0374 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0375 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14901 Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4ISVNIC44SOGXTUBCIZFSUNQJ5LRKNZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MN6MLCN7G7VFTSXSZYXKXEFCUMFBUAXQ/
- https://usn.ubuntu.com/4225-1/ Third Party Advisory
- https://usn.ubuntu.com/4225-2/ Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
16.91%
Top 3% most likely to be exploited
Threat Score
44.3 / 100
Data Sources
NVD
EPSS
GitHub