Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-15594

Опубликовано: 20 авг. 2018
Источник: debian
EPSS Низкий

Описание

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.17.15-1package

Примечания

  • https://twitter.com/grsecurity/status/1029324426142199808

  • https://git.kernel.org/linus/5800dc5c19f34e6e03b5adab1282535cb102fafd

EPSS

Процентиль: 4%
0.00022
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.

CVSS3: 5.6
redhat
почти 7 лет назад

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.

CVSS3: 5.5
nvd
почти 7 лет назад

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.

CVSS3: 5.5
github
около 3 лет назад

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.

CVSS3: 5.5
fstec
почти 7 лет назад

Уязвимость в файле arch/x86/kernel/paravirt.c ядра операционной системы Linux, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 4%
0.00022
Низкий