PT-2019-4449 · Linux+3 · Linux Kernel+3

Brad Spengler

·

Published

2016-03-17

·

Updated

2024-06-15

·

CVE-2019-15902

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions 4.4.x through 4.4.190 Linux kernel versions 4.9.x through 4.9.190 Linux kernel versions 4.14.x through 4.14.141 Linux kernel versions 4.19.x through 4.19.69 Linux kernel versions 5.2.x through 5.2.11
Description The issue is related to errors in implementing protections against Spectre class vulnerabilities in the Linux kernel's ptrace subsystem. Exploitation of this issue may allow an attacker to disclose protected information. A backporting error in the Linux stable/longterm kernel reintroduced a Spectre vulnerability that was supposed to be eliminated. This occurred due to the misuse of an upstream commit and the swapping of two correctly ordered code lines.
Recommendations For Linux kernel versions 4.4.x through 4.4.190, update to a version after 4.4.190 to resolve the issue. For Linux kernel versions 4.9.x through 4.9.190, update to a version after 4.9.190 to resolve the issue. For Linux kernel versions 4.14.x through 4.14.141, update to a version after 4.14.141 to resolve the issue. For Linux kernel versions 4.19.x through 4.19.69, update to a version after 4.19.69 to resolve the issue. For Linux kernel versions 5.2.x through 5.2.11, update to a version after 5.2.11 to resolve the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1262
ALT-PU-2017-1299
ALT-PU-2018-1557
ALT-PU-2019-1139
ALT-PU-2019-1363
ALT-PU-2019-2655
ALT-PU-2019-2656
ALT-PU-2019-2657
ALT-PU-2019-2768
ALT-PU-2019-2770
ALT-PU-2020-1024
BDU:2020-00236
CVE-2019-15902
DLA-1940-1
DSA-4531-1
OPENSUSE-SU-2019:2173-1
OPENSUSE-SU-2019:2181-1
OPENSUSE-SU-2019_2173-1
OPENSUSE-SU-2019_2181-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
SUSE-SU-2019:14218-1
SUSE-SU-2019:2412-1
SUSE-SU-2019:2414-1
SUSE-SU-2019:2424-1
SUSE-SU-2019:2648-1
SUSE-SU-2019:2651-1
SUSE-SU-2019:2658-1
SUSE-SU-2019:2738-1
SUSE-SU-2019:2756-1
SUSE-SU-2019:2949-1
SUSE-SU-2019:2950-1
SUSE-SU-2019:2984-1
SUSE-SU-2019_14218-1
USN-4157-1
USN-4157-2
USN-4162-1
USN-4162-2
USN-4163-1
USN-4163-2

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu