PT-2018-17242 · Linux+1 · Linux Kernel+1

Publicado

2018-01-24

·

Atualizado

2025-09-29

·

CVE-2018-5953

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.14.15
Description: The issue allows local users to obtain sensitive address information. This is achieved by reading dmesg data from a "software IO TLB" printk call, specifically through the swiotlb print info function in lib/swiotlb.c.
Recommendations: For Linux kernel versions prior to 4.14.15, update to version 4.14.15 or later to resolve the issue. As a temporary workaround, consider restricting access to dmesg data to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2018-1077
ALT-PU-2018-1991
CVE-2018-5953
DLA-1731-1
DLA-1731-2

Produtos afetados

Alt Linux
Linux Kernel