Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r297-r893-jqqx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.

In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.

EPSS

Процентиль: 35%
0.00419
Низкий

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 5 лет назад

In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.

CVSS3: 4.4
redhat
около 5 лет назад

In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.

CVSS3: 5.5
nvd
около 5 лет назад

In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.

CVSS3: 5.5
msrc
почти 5 лет назад

In the Linux kernel through 5.13.7 an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.

CVSS3: 5.5
debian
около 5 лет назад

In the Linux kernel through 5.13.7, an unprivileged BPF program can ob ...

EPSS

Процентиль: 35%
0.00419
Низкий

Дефекты

CWE-203