Количество 13
Количество 13

CVE-2018-19854
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).

CVE-2018-19854
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).

CVE-2018-19854
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
CVE-2018-19854
An issue was discovered in the Linux kernel before 4.19.3. crypto_repo ...
GHSA-328v-h46x-hhhx
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).

BDU:2019-01062
Уязвимость функции crypto_report_one() ядра операционной системы Linux, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

SUSE-SU-2019:0196-1
Security update for the Linux Kernel

openSUSE-SU-2019:0065-1
Security update for the Linux Kernel

SUSE-SU-2019:0150-1
Security update for the Linux Kernel

SUSE-SU-2019:0224-1
Security update for the Linux Kernel

SUSE-SU-2019:0222-1
Security update for the Linux Kernel
ELSA-2020-5676
ELSA-2020-5676: Unbreakable Enterprise kernel security update (IMPORTANT)
ELSA-2019-3517
ELSA-2019-3517: kernel security, bug fix, and enhancement update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2018-19854 An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option). | CVSS3: 4.7 | 0% Низкий | больше 6 лет назад |
![]() | CVE-2018-19854 An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option). | CVSS3: 3.3 | 0% Низкий | больше 6 лет назад |
![]() | CVE-2018-19854 An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option). | CVSS3: 4.7 | 0% Низкий | больше 6 лет назад |
CVE-2018-19854 An issue was discovered in the Linux kernel before 4.19.3. crypto_repo ... | CVSS3: 4.7 | 0% Низкий | больше 6 лет назад | |
GHSA-328v-h46x-hhhx An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option). | CVSS3: 4.7 | 0% Низкий | около 3 лет назад | |
![]() | BDU:2019-01062 Уязвимость функции crypto_report_one() ядра операционной системы Linux, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 4.7 | 0% Низкий | больше 6 лет назад |
![]() | SUSE-SU-2019:0196-1 Security update for the Linux Kernel | больше 6 лет назад | ||
![]() | openSUSE-SU-2019:0065-1 Security update for the Linux Kernel | около 6 лет назад | ||
![]() | SUSE-SU-2019:0150-1 Security update for the Linux Kernel | больше 6 лет назад | ||
![]() | SUSE-SU-2019:0224-1 Security update for the Linux Kernel | больше 6 лет назад | ||
![]() | SUSE-SU-2019:0222-1 Security update for the Linux Kernel | больше 6 лет назад | ||
ELSA-2020-5676 ELSA-2020-5676: Unbreakable Enterprise kernel security update (IMPORTANT) | около 5 лет назад | |||
ELSA-2019-3517 ELSA-2019-3517: kernel security, bug fix, and enhancement update (IMPORTANT) | больше 5 лет назад |
Уязвимостей на страницу