Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-18660

Опубликовано: 28 нояб. 2019
Источник: redhat
CVSS3: 4.7

Описание

The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.

A flaw was found in the way the Linux kernel implemented a software flush of the Count Cache (indirect branch cache) and Link (Return Address) Stack on the PowerPC platform. The flushing of these structures helps to prevent SpectreRSB like attacks which may leak information from one user process to another. An unprivileged user could use this flaw to cross the syscall or process boundary and read privileged memory by conducting targeted cache side-channel attacks.

Отчет

This issue affects versions of the kernel package as shipped with Red Hat Enterprise Linux 6, 7 and 8. Future kernel updates for Red Hat Enterprise Linux 6, 7 and 8 may address this issue. This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise MRG 2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernel-rtAffected
Red Hat Enterprise MRG 2kernel-rtNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2020:293315.07.2020
Red Hat Enterprise Linux 7kernel-altFixedRHSA-2020:017421.01.2020
Red Hat Enterprise Linux 7kernelFixedRHSA-2020:101631.03.2020
Red Hat Enterprise Linux 7.6 Extended Update SupportkernelFixedRHSA-2020:285107.07.2020
Red Hat Enterprise Linux 7.7 Extended Update SupportkernelFixedRHSA-2020:198430.04.2020
Red Hat Enterprise Linux 8kernelFixedRHSA-2020:137207.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1777825kernel: powerpc: incomplete Spectre-RSB mitigation leads to information exposure

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 5 лет назад

The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.

CVSS3: 4.7
nvd
больше 5 лет назад

The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.

CVSS3: 4.7
debian
больше 5 лет назад

The Linux kernel before 5.4.1 on powerpc allows Information Exposure b ...

CVSS3: 4.7
github
около 3 лет назад

The Linux kernel through 5.3.13 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.

oracle-oval
почти 5 лет назад

ELSA-2020-2933: kernel security and bug fix update (MODERATE)

4.7 Medium

CVSS3