Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13233

Опубликовано: 04 июл. 2019
Источник: debian
EPSS Низкий

Описание

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.2.6-1package
linuxnot-affectedstretchpackage
linuxnot-affectedjessiepackage

Примечания

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1879

  • Fixed by: https://git.kernel.org/linus/de9f869616dd95e95c00bdd6b0fcd3421e8a4323

EPSS

Процентиль: 22%
0.00068
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
около 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

CVSS3: 5.1
redhat
около 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

CVSS3: 7
nvd
около 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

suse-cvrf
почти 6 лет назад

Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP1)

CVSS3: 7
github
около 3 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

EPSS

Процентиль: 22%
0.00068
Низкий