Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2085

Опубликовано: 27 апр. 2016
Источник: debian
EPSS Низкий

Описание

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.4.2-1package
linuxfixed3.16.7-ckt25-1jessiepackage
linux-2.6removedpackage

Примечания

  • EVM is not enabled

  • https://git.kernel.org/linus/613317bd212c585c20796c10afe5daaa95d4b0a1 (v4.5-rc4)

EPSS

Процентиль: 22%
0.00072
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 10 лет назад

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

redhat
почти 10 лет назад

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

CVSS3: 5.5
nvd
почти 10 лет назад

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

CVSS3: 5.5
github
больше 3 лет назад

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

EPSS

Процентиль: 22%
0.00072
Низкий