Linux KVM's mitigation for Intel Transaction Asynchronous Abort (TAA), tracked as CVE-2019-11135, was found incomplete and assigned CVE-2019-19338. On TAA-vulnerable Cascade Lake hosts with TSX enabled but unaffected by Microarchitectural Data Sampling (MDS), KVM could expose MDS_NO=1 to guests, causing them to omit the required VERW-based clearing of CPU buffers despite remaining susceptible to TAA. Upstream fixes export MSR_IA32_TSX_CTRL to guests or, alternatively, report MDS_NO=0 when TSX remains enabled; KVM also uses the control MSR to disable RTM in guests when the host does not expose it.
Red Hat released updated qemu-kvm packages for RHEL 7 through RHSA-2020:0366 to address the TAA issue, the KVM architectural-capabilities/CPUID exposure problem, and QEMU slirp heap buffer overflow CVE-2019-14378. Administrators should install the update and fully shut down and restart every running virtual machine, as guest restarts are required for the new CPU-feature and mitigation exposure settings to take effect.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2020:0366 for RHEL 7, providing updated qemu-kvm packages that remediate Intel TAA (CVE-2019-11135) and the QEMU slirp heap buffer overflow CVE-2019-14378. The update also addressed KVM architectural-capabilities CPUID exposure and added MDS_NO exposure to guest VMs; administrators were instructed to restart all VMs after installation.
Red Hat assigned CVE-2019-19338 to an incomplete Linux KVM mitigation for Intel Transactional Asynchronous Abort (CVE-2019-11135). On TAA-vulnerable Cascade Lake hosts with TSX enabled and MDS_NO=1, guests could be prevented from using VERW to clear affected CPU buffers.
An upstream Linux KVM VMX patch added handling for the guest MSR_IA32_TSX_CTRL, disabling RTM/TSX for guests when RTM is not exposed and centralizing shared guest-MSR updates. The patch was among upstream changes provided to address the incomplete TAA mitigation scenario.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceopenwall.com
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.