Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20908

Опубликовано: 15 июл. 2020
Источник: debian
EPSS Низкий

Описание

An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.2.6-1package
linuxfixed4.19.132-1busterpackage
linuxignoredstretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2020/06/14/1

  • Fixed by: https://git.kernel.org/linus/1957a85b0032a81e6482ca4aab883643b8dae06e

EPSS

Процентиль: 4%
0.00023
Низкий

Связанные уязвимости

CVSS3: 6.7
ubuntu
почти 5 лет назад

An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.

CVSS3: 6.4
redhat
почти 6 лет назад

An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.

CVSS3: 6.7
nvd
почти 5 лет назад

An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.

github
около 3 лет назад

An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.

oracle-oval
почти 5 лет назад

ELSA-2020-5791: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 4%
0.00023
Низкий