PT-2019-1115 · Linux+5 · Linux Kernel+5
Published
2019-01-06
·
Updated
2025-09-29
·
CVE-2019-5489
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions through 4.19.13
Description:
The issue is related to the mincore() function in the Linux kernel, which lacks protection of internal data. This could allow an attacker to disclose protected information by observing page cache access patterns of other processes on the same system. Limited remote exploitation may be possible, potentially allowing the sniffing of secret information. The vulnerability could be exploited to conduct a page-cache side-channel attack, enabling the attacker to view page-cache access patterns and access sensitive information.
Recommendations:
For Linux kernel versions through 4.19.13, update to a version that includes the fix for this issue to prevent exploitation.
As a temporary workaround, consider restricting access to sensitive information and limiting the use of the mincore() function until a patch is available.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Huawei Vrp
Linux Kernel
Red Hat
Suse