5.6

CVE-2019-15902

Exploit
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.4 <= 4.4.190
Linux ≫ Linux Kernel Version >= 4.9 <= 4.9.190
Linux ≫ Linux Kernel Version >= 4.14 <= 4.14.141
Linux ≫ Linux Kernel Version >= 4.19 <= 4.19.69
Linux ≫ Linux Kernel Version >= 5.2 <= 5.2.11
Netapp ≫ Service Processor Version -
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.433
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.6 1.1 4
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
NIST 4.7 3.4 6.9
AV:L/AC:M/Au:N/C:C/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://usn.ubuntu.com/4163-1/
https://usn.ubuntu.com/4163-2/
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/10/msg00000.html
Third Party Advisory
https://seclists.org/bugtraq/2019/Sep/41
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4162-1/
https://usn.ubuntu.com/4162-2/
https://www.debian.org/security/2019/dsa-4531
Third Party Advisory
https://usn.ubuntu.com/4157-1/
https://usn.ubuntu.com/4157-2/
https://security.netapp.com/advisory/ntap-20191004-0001/
Third Party Advisory
https://grsecurity.net/teardown_of_a_failed_linux_lts_spectre_fix.php
Patch
Third Party Advisory
Exploit