Описание
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.13.0-16.19 |
| devel | not-affected | 5.8.0-34.37+21.04.1 |
| esm-infra-legacy/trusty | ignored | was needs-triage ESM criteria |
| esm-infra/bionic | not-affected | 4.13.0-16.19 |
| esm-infra/focal | not-affected | 5.4.0-9.12 |
| esm-infra/xenial | not-affected | 4.2.0-16.19 |
| focal | not-affected | 5.4.0-9.12 |
| groovy | not-affected | 5.4.0-26.30 |
| precise/esm | ignored | end of life, was needs-triage |
| trusty | ignored | end of standard support |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.15.0-1001.1 |
| devel | not-affected | 5.8.0-1017.18+21.04.2 |
| esm-infra-legacy/trusty | ignored | was needs-triage ESM criteria |
| esm-infra/bionic | not-affected | 4.15.0-1001.1 |
| esm-infra/focal | not-affected | 5.4.0-1005.5 |
| esm-infra/xenial | not-affected | 4.4.0-1001.10 |
| focal | not-affected | 5.4.0-1005.5 |
| groovy | not-affected | 5.4.0-1009.9 |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | ignored | superseded by linux-aws-5.3, was needs-triage |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.3.0-1016.17~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.3.0-1016.17~18.04.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.4.0-1018.18~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.4.0-1018.18~18.04.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| esm-infra/xenial | not-affected | 4.15.0-1030.31~16.04.1 |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | not-affected | 5.8.0-1016.17+21.04.1 |
| esm-infra-legacy/trusty | ignored | was needs-triage ESM criteria |
| esm-infra/bionic | ignored | superseded by linux-azure-5.3, was needs-triage |
| esm-infra/focal | not-affected | 5.4.0-1006.6 |
| esm-infra/xenial | not-affected | 4.11.0-1009.9 |
| focal | not-affected | 5.4.0-1006.6 |
| groovy | not-affected | 5.4.0-1010.10 |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.15.0-1082.92 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 4.15.0-1082.92 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.3.0-1007.8~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.3.0-1007.8~18.04.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.4.0-1020.20~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.4.0-1020.20~18.04.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | ignored | superseded by linux-azure-5.3, was needs-triage |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | not-affected | 5.8.0-1015.15+21.04.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | ignored | superseded by linux-gcp-5.3, was needs-triage |
| esm-infra/focal | not-affected | 5.4.0-1005.5 |
| esm-infra/xenial | not-affected | 4.10.0-1004.4 |
| focal | not-affected | 5.4.0-1005.5 |
| groovy | not-affected | 5.4.0-1009.9 |
| precise/esm | DNE | |
| trusty | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.15.0-1071.81 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 4.15.0-1071.81 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | ignored | superseded by linux-gcp-5.4, was needs-triage |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.4.0-1019.19~18.04.2 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.4.0-1019.19~18.04.2 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | ignored | end of kernel support, was needs-triage |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.15.0-1030.32 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 4.15.0-1030.32 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.0.0-1011.11~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.3.0-1011.12~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.4.0-1025.25~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.4.0-1025.25~18.04.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.4.0-1001.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.4.0-1001.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.18.0-13.14~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 4.18.0-13.14~18.04.1 |
| esm-infra/focal | DNE | |
| esm-infra/xenial | not-affected | 4.8.0-36.36~16.04.1 |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.4.0-37.41~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.4.0-37.41~18.04.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | not-affected | 5.8.0-23.24~20.04.1 |
| focal | not-affected | 5.8.0-23.24~20.04.1 |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | ignored | superseded by linux-hwe-5.4, was needs-triage |
| esm-infra/focal | DNE | |
| esm-infra/xenial | ignored | superseded by linux-hwe, was needs-triage |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.15.0-1002.2 |
| devel | not-affected | 5.8.0-1010.11+21.04.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 4.15.0-1002.2 |
| esm-infra/focal | not-affected | 5.4.0-1004.4 |
| esm-infra/xenial | not-affected | 4.4.0-1004.9 |
| focal | not-affected | 5.4.0-1004.4 |
| groovy | not-affected | 5.4.0-1009.9 |
| precise/esm | DNE | |
| trusty | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | ignored | end of life, was needs-triage |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | ignored | was needs-triage ESM criteria |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | ignored | end of ESM support, was ignored [was needs-triage ESM criteria] |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.15.0-1002.3 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 4.15.0-1002.3 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | released | 5.6.0-1023.23 |
| focal | released | 5.6.0-1023.23 |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.0.0-1010.11 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.15.0-1007.9 |
| devel | not-affected | 5.8.0-1014.14+21.04.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 4.15.0-1007.9 |
| esm-infra/focal | not-affected | 5.4.0-1005.5 |
| esm-infra/xenial | not-affected | 4.15.0-1007.9~16.04.1 |
| focal | not-affected | 5.4.0-1005.5 |
| groovy | not-affected | 5.4.0-1009.9 |
| precise/esm | DNE | |
| trusty | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | ignored | superseded by linux-oracle-5.3, was needs-triage |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | ignored | superseded by linux-oracle-5.4, was needs-triage |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.4.0-1019.19~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.4.0-1019.19~18.04.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | not-affected | 5.8.0-1008.11+21.04.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | not-affected | 5.4.0-1007.7 |
| focal | not-affected | 5.4.0-1007.7 |
| groovy | not-affected | 5.4.0-1008.8 |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.4.0-1013.13~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | 5.4.0-1013.13~18.04.1 |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.13.0-1005.5 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | ignored | replaced by linux-raspi |
| focal | ignored | end of standard support, was needs-triage |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 5.3.0-1017.19~18.04.1 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | not-affected | 5.8.0-10.12+21.04.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | not-affected | 5.4.0-24.28 |
| focal | not-affected | 5.4.0-24.28 |
| groovy | not-affected | 5.4.0-24.28 |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 4.4.0-1077.82 |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 5.8~rc6 |
Показывать по
Ссылки на источники
EPSS
4.6 Medium
CVSS2
7.8 High
CVSS3
Связанные уязвимости
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used ...
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
Уязвимость функции tss_invalidate_io_bitmap ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии
EPSS
4.6 Medium
CVSS2
7.8 High
CVSS3