Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11135

Опубликовано: 14 нояб. 2019
Источник: debian
EPSS Низкий

Описание

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.3.9-2package
intel-microcodefixed3.20191112.1package
xenfixed4.11.3+24-g14b62ab3e5-1package
xenend-of-lifejessiepackage

Примечания

  • https://software.intel.com/security-software-guidance/insights/deep-dive-intel-transactional-synchronization-extensions-intel-tsx-asynchronous-abort

  • https://xenbits.xen.org/xsa/advisory-305.html

  • The 3.20191112.1 release for intel-microcode did contain most updates, additional

  • update for CFL-S was added in 3.20191113.1.

EPSS

Процентиль: 60%
0.00394
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

CVSS3: 6.5
redhat
больше 5 лет назад

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

CVSS3: 6.5
nvd
больше 5 лет назад

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

CVSS3: 4.7
msrc
больше 5 лет назад

Windows Kernel Information Disclosure Vulnerability

rocky
больше 5 лет назад

Moderate: virt:rhel security update

EPSS

Процентиль: 60%
0.00394
Низкий