CVE-2019-19338
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2019-19338 is a vulnerability discovered in the Linux kernel's implementation of the fix for CVE-2019-11135 (TAA - TSX Asynchronous Abort). The vulnerability affects guest virtual machines running on host systems with Intel Cascade Lake CPUs that have TSX (Transactional Synchronization Extensions) enabled. The issue was identified in Linux kernel versions before 5.5 (NVD, OSS Security).

Technical details

The vulnerability stems from an incomplete fix for the TAA (Transaction Asynchronous Abort) hardware issue. When a guest is running on a host CPU affected by TAA (TAA_NO=0) but not affected by MDS (MDS_NO=1), the guest was supposed to clear affected buffers using the VERW instruction mechanism. However, when the MDS_NO=1 bit was exported to guests, they failed to implement the VERW mechanism to clear the affected Store/Fill/Load port architectural buffers. The vulnerability has a CVSS v3.1 base score of 5.5 (Medium) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N (NVD).

Impact

The primary impact of this vulnerability is the potential exposure of sensitive information through the affected architectural buffers. The vulnerability specifically affects confidentiality, with no direct impact on integrity or availability. This issue particularly affects guests running on Cascade Lake CPUs that are affected by TAA but not by MDS, and requires that the host has TSX enabled (OSS Security).

Exploitability

The vulnerability requires local access and can only be exploited under specific conditions: the system must be running on Cascade Lake CPUs affected by TAA (TAA_NO=0) but not by MDS (MDS_NO=1), and must have TSX enabled on the host system (Red Hat Bugzilla).

Mitigation and workarounds

The vulnerability was fixed in Linux kernel version 5.5. Multiple patches were implemented upstream, including: setting MDS_NO=0 for guests when TSX is enabled and updating the handling of MSR_IA32_TSX_CTRL for guest VMs. Red Hat has released security updates addressing this vulnerability through various errata including RHSA-2020:1465 for RHEL 7.6 Extended Update Support (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74726NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-modules
NoYesAug 22, 2026
CVE-2026-74719NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-partner
NoYesAug 22, 2026
CVE-2026-74717NONEN/A
  • Linux Kernel logoLinux Kernel
  • rtla
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management