Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2cx-8gq2-993w

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR.

The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR.

EPSS

Процентиль: 21%
0.00066
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR.

CVSS3: 3.3
redhat
почти 8 лет назад

The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR.

CVSS3: 5.5
nvd
почти 8 лет назад

The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR.

CVSS3: 5.5
debian
почти 8 лет назад

The move_pages system call in mm/migrate.c in the Linux kernel before ...

oracle-oval
больше 7 лет назад

ELSA-2018-4025: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 21%
0.00066
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200