PT-2019-5421 · Linux+5 · Linux Kernel+5

Anthony Steinhauser

·

Publicado

2019-11-14

·

Atualizado

2021-05-28

·

CVE-2019-18660

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.4.1
Description The issue is related to Information Exposure due to the lack of Spectre-RSB mitigation for all applicable CPUs. This concern is tied to the components arch/powerpc/kernel/entry 64.S and arch/powerpc/kernel/security.c in the Linux kernel. The vulnerability allows an attacker to potentially gain unauthorized access to information by exploiting data left in the processor cache due to speculative instruction execution.
Recommendations For Linux kernel versions prior to 5.4.1, update to version 5.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and resources until the update can be applied.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3207
ALT-PU-2019-3236
ALT-PU-2019-3268
ALT-PU-2019-3272
ALT-PU-2019-3293
ALT-PU-2019-3343
ALT-PU-2019-3369
ALT-PU-2020-1025
ALT-PU-2020-1028
ALT-PU-2020-1070
ALT-PU-2020-1198
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-1501
ALT-PU-2020-1714
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1745
ALT-PU-2021-1870
BDU:2020-02944
CESA-2020_1016
CESA-2020_1372
CVE-2019-18660
OPENSUSE-SU-2019:2675-1
OPENSUSE-SU-2019_2675-1
RHSA-2020:0174
RHSA-2020:1016
RHSA-2020:1372
RHSA-2020:1984
RHSA-2020:2429
RHSA-2020:2851
RHSA-2020:2933
RHSA-2020_1016
RHSA-2020_1372
RHSA-2020_2933
SUSE-SU-2019:3200-1
SUSE-SU-2019:3289-1
SUSE-SU-2019:3316-1
SUSE-SU-2019:3317-1
SUSE-SU-2019:3371-1
SUSE-SU-2019:3372-1
SUSE-SU-2019:3379-1
SUSE-SU-2019:3381-1
SUSE-SU-2020:0093-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1255-1
SUSE-SU-2020:14354-1
USN-4225-1
USN-4225-2
USN-4226-1
USN-4227-1
USN-4227-2
USN-4228-1
USN-4228-2

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu