Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5953

Опубликовано: 07 авг. 2018
Источник: redhat
CVSS3: 0

Описание

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.

A flaw was found in the Linux kernel where the swiotlb_print_info() function in lib/swiotlb.c allows local users to obtain some kernel address information by reading the kernel log (dmesg). This address is not useful to commit a further attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1614057kernel: Information Exposure through dmesg data from a "software IO TLB" printk call

0 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.

CVSS3: 5.5
nvd
почти 7 лет назад

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.

CVSS3: 5.5
debian
почти 7 лет назад

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel t ...

CVSS3: 5.5
github
около 3 лет назад

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.

oracle-oval
около 5 лет назад

ELSA-2020-5644: Unbreakable Enterprise kernel security update (IMPORTANT)

0 Low

CVSS3