Red Hat Enterprise Linux 7.6 update for qemu-kvm

Published: 2020-03-04
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2019-11135
Exploitation vector Local
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Red Hat Enterprise Linux Server
Operating systems & Components / Operating system

Vendor Red Hat Inc.

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Resource management error

EUVDB-ID: #VU22704

Risk: Low


CVE-ID: CVE-2019-11135

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No


The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the TSX Asynchronous Abort (TAA) in Intel CPUs. The TAA condition, on some microprocessors utilizing speculative execution, may allow an authenticated user to potentially enable information disclosure via a side channel.


Install updates from vendor's website.

Vulnerable software versions

Red Hat Enterprise Linux Server: 7.6

CPE2.3 External links

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?