Red Hat Enterprise Linux Advanced Virtualization security update for virt:8.1 and virt-devel:8.1 modules

Published: 2020-02-20
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2019-11135
Exploitation vector Local
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Red Hat Virtualization
Server applications / Virtualization software

Vendor Red Hat Inc.

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Resource management error

EUVDB-ID: #VU22704

Risk: Low


CVE-ID: CVE-2019-11135

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No


The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the TSX Asynchronous Abort (TAA) in Intel CPUs. The TAA condition, on some microprocessors utilizing speculative execution, may allow an authenticated user to potentially enable information disclosure via a side channel.


Install updates from vendor's website.

Vulnerable software versions

Red Hat Virtualization: 8

CPE2.3 External links

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?