Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2085

Опубликовано: 11 фев. 2016
Источник: redhat
CVSS2: 4.7
EPSS Низкий

Описание

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

Отчет

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4,5 and 6. This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 7 and kernel-rt packages and does not plan to be addressed in a future update.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelNot affected
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelWill not fix
Red Hat Enterprise Linux 7kernel-rtWill not fix
Red Hat Enterprise MRG 2realtime-kernelWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1324867kernel: timing side channel vulnerability in the Linux Extended Verification Module

EPSS

Процентиль: 22%
0.00072
Низкий

4.7 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 10 лет назад

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

CVSS3: 5.5
nvd
почти 10 лет назад

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

CVSS3: 5.5
debian
почти 10 лет назад

The evm_verify_hmac function in security/integrity/evm/evm_main.c in t ...

CVSS3: 5.5
github
больше 3 лет назад

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

EPSS

Процентиль: 22%
0.00072
Низкий

4.7 Medium

CVSS2