Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-7222

Опубликовано: 07 фев. 2019
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

An information leakage issue was found in the way Linux kernel's KVM hypervisor handled page fault exceptions while emulating instructions like VMXON, VMCLEAR, VMPTRLD, and VMWRITE with memory address as an operand. It occurs if the operand is a mmio address, as the returned exception object holds uninitialized stack memory contents. A guest user/process could use this flaw to leak host's stack memory contents to a guest.

Отчет

This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG 2. This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 7. Future kernel updates for Red Hat Enterprise Linux 7 may address this issue. Note:- Impact on Red Hat Enterprise Linux 7 kernel is limited, as it requires that nested virtualization feature is enabled on a system. Nested Virtualization feature is available only as - Technology Preview.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise MRG 2kernel-rtNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2019:204307.08.2019
Red Hat Enterprise Linux 7kernelFixedRHSA-2019:202906.08.2019
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2019:330905.11.2019
Red Hat Enterprise Linux 8kernelFixedRHSA-2019:351705.11.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1671930Kernel: KVM: leak of uninitialized stack contents to guest

EPSS

Процентиль: 8%
0.00034
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

CVSS3: 5.5
nvd
около 6 лет назад

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

CVSS3: 5.5
debian
около 6 лет назад

The KVM implementation in the Linux kernel through 4.20.5 has an Infor ...

CVSS3: 5.5
github
около 3 лет назад

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость ядра операционной системы Linux, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 8%
0.00034
Низкий

2.8 Low

CVSS3