Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7308

Опубликовано: 01 фев. 2019
Источник: debian
EPSS Низкий

Описание

kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.19.20-1package
linuxnot-affectedstretchpackage
linuxnot-affectedjessiepackage

Примечания

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1711

  • Fixed by: https://git.kernel.org/linus/979d63d50c0c0f7bc537bf821e056cc9fe5abd38

  • Fixed by: https://git.kernel.org/linus/d3bd7413e0ca40b60cf60d4003246d067cafdeda

EPSS

Процентиль: 14%
0.00047
Низкий

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 6 лет назад

kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.

CVSS3: 5.6
redhat
больше 6 лет назад

kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.

CVSS3: 5.6
nvd
больше 6 лет назад

kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.

CVSS3: 5.6
github
около 3 лет назад

kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.

CVSS3: 5.6
fstec
больше 6 лет назад

Уязвимость ядра операционных систем Linux, связанная со смещением указателя за пределы допустимых значений, позволяющая нарушителю реализовать атаки по побочным каналам

EPSS

Процентиль: 14%
0.00047
Низкий