Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
Astra Linux SE 1.5
Astra Linux SE 1.6
Astra Linux SE 1.7
Astra Linux SE 1.8
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:ru.altx-soft.nix:def:131579
[Eng]
Version
7
Class
patch
ALTXid
324998
Language
Russian
Severity
High
Title
Обновление SUSE-SU-2020:1275-1 -- устранение уязвимостей в the Linux Kernel
Description
The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes.
Family
unix
Platform
SUSE Linux Enterprise Server 12
Product
the Linux Kernel
Reference
VENDOR: SUSE-SU-2020:1275-1
VENDOR: SUSE-SU-2020:1275-1
Id:
SUSE-SU-2020:1275-1
Reference:
https://www.suse.com/support/update/announcement/2020/suse-su-20201275-1.html
CVE: CVE-2020-11494
CVE: CVE-2020-11494
Id:
CVE-2020-11494
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11494
Comment
: An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE:
908 ()
References:
https://github.com/torvalds/linux/commit/b9258a2cece4ec1f020715fe3554bc2e360f6264 (MISC)
openSUSE-SU-2020:0543 (SUSE)
https://security.netapp.com/advisory/ntap-20200430-0004/ (CONFIRM)
USN-4364-1 (UBUNTU)
USN-4368-1 (UBUNTU)
USN-4363-1 (UBUNTU)
USN-4369-1 (UBUNTU)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
http://packetstormsecurity.com/files/159565/Kernel-Live-Patch-Security-Notice-LSN-0072-1.html (MISC)
https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=08fadc32ce6239dc75fd5e869590e29bc62bbc28 (MISC)
CVE: CVE-2020-10942
CVE: CVE-2020-10942
Id:
CVE-2020-10942
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10942
Comment
: In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
CVSSv2 Score:
5.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:C
CVSSv3 Score:
5.3
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
LOW
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://lkml.org/lkml/2020/2/15/125 (MISC)
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.8 (MISC)
https://git.kernel.org/linus/42d84c8490f9f0931786f1623191fcab397c3d64 (MISC)
https://security.netapp.com/advisory/ntap-20200403-0003/ (CONFIRM)
[oss-security] 20200415 CVE-2020-10942 Kernel: vhost-net: stack overflow in get_raw_socket while checking sk_family field (MLIST)
openSUSE-SU-2020:0543 (SUSE)
DSA-4667 (DEBIAN)
USN-4344-1 (UBUNTU)
USN-4345-1 (UBUNTU)
USN-4342-1 (UBUNTU)
USN-4364-1 (UBUNTU)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
CVE: CVE-2020-8647
CVE: CVE-2020-8647
Id:
CVE-2020-8647
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8647
Comment
: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
CVSSv2 Score:
3.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:P
CVSSv3 Score:
6.1
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
LOW
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
CWE:
416 (Use After Free)
References:
https://bugzilla.kernel.org/show_bug.cgi?id=206359 (MISC)
openSUSE-SU-2020:0388 (SUSE)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
CVE: CVE-2020-8649
CVE: CVE-2020-8649
Id:
CVE-2020-8649
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8649
Comment
: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
CVSSv2 Score:
3.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:P
CVSSv3 Score:
5.9
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE:
416 (Use After Free)
References:
https://bugzilla.kernel.org/show_bug.cgi?id=206357 (MISC)
openSUSE-SU-2020:0388 (SUSE)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
CVE: CVE-2020-9383
CVE: CVE-2020-9383
Id:
CVE-2020-9383
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9383
Comment
: An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.
CVSSv2 Score:
3.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:P
CVSSv3 Score:
7.1
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE:
125 (Out-of-bounds Read)
References:
https://github.com/torvalds/linux/commit/2e90ca68b0d2f5548804f22f0dd61145516171e3 (MISC)
https://security.netapp.com/advisory/ntap-20200313-0003/ (CONFIRM)
openSUSE-SU-2020:0388 (SUSE)
USN-4344-1 (UBUNTU)
USN-4345-1 (UBUNTU)
USN-4342-1 (UBUNTU)
USN-4346-1 (UBUNTU)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=2f9ac30a54dc0181ddac3705cdcf4775d863c530 (MISC)
CVE: CVE-2019-9458
CVE: CVE-2019-9458
Id:
CVE-2019-9458
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9458
Comment
: In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSSv2 Score:
4.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P
CVSSv3 Score:
7
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
https://source.android.com/security/bulletin/pixel/2019-09-01 (MISC)
openSUSE-SU-2020:0543 (SUSE)
CVE: CVE-2019-3701
CVE: CVE-2019-3701
Id:
CVE-2019-3701
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3701
Comment
: An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes the data length code a higher value than the available CAN frame data size. In combination with a configured checksum calculation where the result is stored relatively to the end of the data (e.g. cgw_csum_xor_rel) the tail of the skb (e.g. frag_list pointer in skb_shared_info) can be rewritten which finally can cause a system crash. Because of a missing check, the CAN drivers may write arbitrary content beyond the data registers in the CAN controller's I/O memory when processing can-gw manipulated outgoing frames.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://marc.info/?l=linux-netdev&m=154651842302479&w=2 (MISC)
https://bugzilla.suse.com/show_bug.cgi?id=1120386 (MISC)
106443 (BID)
[debian-lts-announce] 20190327 [SECURITY] [DLA 1731-1] linux security update (MLIST)
[debian-lts-announce] 20190401 [SECURITY] [DLA 1731-2] linux regression update (MLIST)
USN-3932-2 (UBUNTU)
USN-3932-1 (UBUNTU)
https://support.f5.com/csp/article/K17957133 (CONFIRM)
https://marc.info/?l=linux-netdev&m=154661373531512&w=2 (MISC)
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=0aaa81377c5a01f686bcdb8c7a6929a7bf330c68 (MISC)
[debian-lts-announce] 20190503 [SECURITY] [DLA 1771-1] linux-4.9 security update (MLIST)
USN-4115-1 (UBUNTU)
USN-4118-1 (UBUNTU)
openSUSE-SU-2020:0543 (SUSE)
CVE: CVE-2019-19768
CVE: CVE-2019-19768
Id:
CVE-2019-19768
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19768
Comment
: In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
416 (Use After Free)
References:
https://bugzilla.kernel.org/show_bug.cgi?id=205711 (MISC)
https://security.netapp.com/advisory/ntap-20200103-0001/ (CONFIRM)
openSUSE-SU-2020:0388 (SUSE)
USN-4344-1 (UBUNTU)
USN-4345-1 (UBUNTU)
USN-4342-1 (UBUNTU)
USN-4346-1 (UBUNTU)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
CVE: CVE-2020-11609
CVE: CVE-2020-11609
Id:
CVE-2020-11609
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11609
Comment
: An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06xx.c and drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid descriptors, as demonstrated by a NULL pointer dereference, aka CID-485b06aadb93.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.3
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=485b06aadb933190f4bc44e006076bc27a23f205 (MISC)
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.1 (MISC)
https://github.com/torvalds/linux/commit/485b06aadb933190f4bc44e006076bc27a23f205 (MISC)
https://security.netapp.com/advisory/ntap-20200430-0004/ (CONFIRM)
USN-4345-1 (UBUNTU)
USN-4364-1 (UBUNTU)
USN-4368-1 (UBUNTU)
USN-4369-1 (UBUNTU)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
openSUSE-SU-2020:0801 (SUSE)
CVE: CVE-2020-10720
CVE: CVE-2020-10720
Id:
CVE-2020-10720
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10720
Comment
: A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
416 (Use After Free)
References:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a4270d6795b0580287453ea55974d948393e66ef (MISC)
https://bugzilla.redhat.com/show_bug.cgi?id=1781204 (MISC)
CVE: CVE-2020-10690
CVE: CVE-2020-10690
Id:
CVE-2020-10690
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10690
Comment
: There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition as the process wakes up to terminate and clean all attached files. The system crashes due to the cdev structure being invalid (as already freed) which is pointed to by the inode.
CVSSv2 Score:
4.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P
CVSSv3 Score:
6.4
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10690 (CONFIRM)
https://security.netapp.com/advisory/ntap-20200608-0001/ (CONFIRM)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
openSUSE-SU-2020:0801 (SUSE)
USN-4419-1 (UBUNTU)
CVE: CVE-2019-9455
CVE: CVE-2019-9455
Id:
CVE-2019-9455
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9455
Comment
: In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
2.3
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
LOW
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE:
209 (Information Exposure Through an Error Message)
References:
https://source.android.com/security/bulletin/pixel/2019-09-01 (MISC)
openSUSE-SU-2020:0801 (SUSE)
CVE: CVE-2020-11608
CVE: CVE-2020-11608
Id:
CVE-2020-11608
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11608
Comment
: An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints, aka CID-998912346c0d.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
4.3
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.1 (MISC)
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=998912346c0da53a6dbb71fab3a138586b596b30 (MISC)
https://github.com/torvalds/linux/commit/998912346c0da53a6dbb71fab3a138586b596b30 (MISC)
https://security.netapp.com/advisory/ntap-20200430-0004/ (CONFIRM)
USN-4345-1 (UBUNTU)
USN-4364-1 (UBUNTU)
USN-4368-1 (UBUNTU)
USN-4369-1 (UBUNTU)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
openSUSE-SU-2020:0801 (SUSE)
CVE: CVE-2017-18255
CVE: CVE-2017-18255
Id:
CVE-2017-18255
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18255
Comment
: The perf_cpu_time_max_percent_handler function in kernel/events/core.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow) or possibly have unspecified other impact via a large value, as demonstrated by an incorrect sample-rate calculation.
CVSSv2 Score:
4.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
190 (Integer Overflow or Wraparound)
References:
https://github.com/torvalds/linux/commit/1572e45a924f254d9570093abde46430c3172e3d (MISC)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1572e45a924f254d9570093abde46430c3172e3d (MISC)
USN-3696-2 (UBUNTU)
USN-3696-1 (UBUNTU)
[debian-lts-announce] 20180718 [SECURITY] [DLA 1423-1] linux-4.9 new package (MLIST)
USN-3754-1 (UBUNTU)
103607 (BID)
CVE: CVE-2020-8648
CVE: CVE-2020-8648
Id:
CVE-2020-8648
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8648
Comment
: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
CVSSv2 Score:
3.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:P
CVSSv3 Score:
7.1
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE:
416 (Use After Free)
References:
https://bugzilla.kernel.org/show_bug.cgi?id=206361 (MISC)
openSUSE-SU-2020:0336 (SUSE)
USN-4344-1 (UBUNTU)
USN-4345-1 (UBUNTU)
USN-4342-1 (UBUNTU)
USN-4346-1 (UBUNTU)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
https://security.netapp.com/advisory/ntap-20200924-0004/ (CONFIRM)
CVE: CVE-2020-2732
CVE: CVE-2020-2732
Id:
CVE-2020-2732
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2732
Comment
: A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
CVSSv2 Score:
2.3
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
SINGLE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:A/AC:M/Au:S/C:P/I:N/A:N
CVSSv3 Score:
6.8
Attack vector:
ADJACENT_NETWORK
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://www.spinics.net/lists/kvm/msg208259.html (MISC)
https://linux.oracle.com/errata/ELSA-2020-5540.html (MISC)
https://linux.oracle.com/errata/ELSA-2020-5542.html (MISC)
https://www.openwall.com/lists/oss-security/2020/02/25/3 (MISC)
https://git.kernel.org/linus/35a571346a94fb93b5b3b6a599675ef3384bc75c (MISC)
https://bugzilla.redhat.com/show_bug.cgi?id=1805135 (MISC)
https://linux.oracle.com/errata/ELSA-2020-5543.html (MISC)
https://git.kernel.org/linus/07721feee46b4b248402133228235318199b05ec (MISC)
https://git.kernel.org/linus/e71237d3ff1abf9f3388337cfebf53b96df2020d (MISC)
DSA-4667 (DEBIAN)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
CVE: CVE-2019-5108
CVE: CVE-2019-5108
Id:
CVE-2019-5108
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5108
Comment
: An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby APs of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.
CVSSv2 Score:
3.3
Access vector:
ADJACENT_NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:A/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6.5
Attack vector:
ADJACENT_NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
287 (Improper Authentication)
References:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0900 (MISC)
https://git.kernel.org/linus/3e493173b7841259a08c5c8e5cbe90adb349da7e (MISC)
https://security.netapp.com/advisory/ntap-20200204-0002/ (CONFIRM)
http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LSN-0063-1.html (MISC)
USN-4285-1 (UBUNTU)
USN-4287-1 (UBUNTU)
USN-4286-2 (UBUNTU)
USN-4287-2 (UBUNTU)
USN-4286-1 (UBUNTU)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
https://www.oracle.com/security-alerts/cpuApr2021.html (MISC)
CVE: CVE-2020-8992
CVE: CVE-2020-8992
Id:
CVE-2020-8992
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8992
Comment
: ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
https://patchwork.ozlabs.org/patch/1236118/ (MISC)
https://security.netapp.com/advisory/ntap-20200313-0003/ (CONFIRM)
openSUSE-SU-2020:0336 (SUSE)
USN-4318-1 (UBUNTU)
USN-4324-1 (UBUNTU)
USN-4344-1 (UBUNTU)
USN-4342-1 (UBUNTU)
USN-4419-1 (UBUNTU)
CVE: CVE-2018-21008
CVE: CVE-2018-21008
Id:
CVE-2018-21008
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-21008
Comment
: An issue was discovered in the Linux kernel before 4.16.7. A use-after-free can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
416 (Use After Free)
References:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=abd39c6ded9db53aa44c2540092bdd5fb6590fa8 (MISC)
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.16.7 (MISC)
openSUSE-SU-2019:2173 (SUSE)
openSUSE-SU-2019:2181 (SUSE)
[debian-lts-announce] 20190925 [SECURITY] [DLA 1930-1] linux security update (MLIST)
https://security.netapp.com/advisory/ntap-20191004-0001/ (CONFIRM)
USN-4162-1 (UBUNTU)
USN-4163-1 (UBUNTU)
USN-4163-2 (UBUNTU)
USN-4162-2 (UBUNTU)
http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html (MISC)
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update (MLIST)
CVE: CVE-2019-14896
CVE: CVE-2019-14896
Id:
CVE-2019-14896
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14896
Comment
: A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.
CVSSv2 Score:
10
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
122 (Heap-based Buffer Overflow)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14896 (CONFIRM)
https://security.netapp.com/advisory/ntap-20200103-0001/ (CONFIRM)
USN-4228-1 (UBUNTU)
USN-4227-1 (UBUNTU)
USN-4225-1 (UBUNTU)
USN-4228-2 (UBUNTU)
USN-4226-1 (UBUNTU)
USN-4227-2 (UBUNTU)
http://packetstormsecurity.com/files/155879/Kernel-Live-Patch-Security-Notice-LSN-0061-1.html (MISC)
[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update (MLIST)
USN-4225-2 (UBUNTU)
http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.html (MISC)
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update (MLIST)
openSUSE-SU-2020:0336 (SUSE)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MN6MLCN7G7VFTSXSZYXKXEFCUMFBUAXQ/ (MISC)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4ISVNIC44SOGXTUBCIZFSUNQJ5LRKNZ/ (MISC)
CVE: CVE-2019-14897
CVE: CVE-2019-14897
Id:
CVE-2019-14897
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14897
Comment
: A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.
CVSSv2 Score:
7.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
121 (Stack-based Buffer Overflow)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14897 (CONFIRM)
USN-4228-1 (UBUNTU)
USN-4225-1 (UBUNTU)
USN-4228-2 (UBUNTU)
USN-4226-1 (UBUNTU)
USN-4227-1 (UBUNTU)
USN-4227-2 (UBUNTU)
http://packetstormsecurity.com/files/155879/Kernel-Live-Patch-Security-Notice-LSN-0061-1.html (MISC)
[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update (MLIST)
USN-4225-2 (UBUNTU)
http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.html (MISC)
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update (MLIST)
openSUSE-SU-2020:0336 (SUSE)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MN6MLCN7G7VFTSXSZYXKXEFCUMFBUAXQ/ (MISC)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4ISVNIC44SOGXTUBCIZFSUNQJ5LRKNZ/ (MISC)
CVE: CVE-2019-18675
CVE: CVE-2019-18675
Id:
CVE-2019-18675
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18675
Comment
: The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
190 (Integer Overflow or Wraparound)
References:
https://deshal3v.github.io/blog/kernel-research/mmap_exploitation (MISC)
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/drivers/media/usb/cpia2/cpia2_core.c (MISC)
https://security.netapp.com/advisory/ntap-20200103-0001/ (CONFIRM)
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=be83bbf806822b1b89e0a0f23cd87cddc409e429 (CONFIRM)
CVE: CVE-2019-14615
CVE: CVE-2019-14615
Id:
CVE-2019-14615
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14615
Comment
: Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00314.html (CONFIRM)
USN-4254-1 (UBUNTU)
USN-4255-1 (UBUNTU)
USN-4253-1 (UBUNTU)
USN-4254-2 (UBUNTU)
USN-4253-2 (UBUNTU)
USN-4255-2 (UBUNTU)
http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.html (MISC)
http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LSN-0063-1.html (MISC)
USN-4285-1 (UBUNTU)
USN-4287-1 (UBUNTU)
USN-4286-2 (UBUNTU)
USN-4287-2 (UBUNTU)
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update (MLIST)
USN-4284-1 (UBUNTU)
USN-4286-1 (UBUNTU)
openSUSE-SU-2020:0336 (SUSE)
https://support.apple.com/kb/HT211100 (CONFIRM)
20200324 APPLE-SA-2020-03-24-2 macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra (FULLDISC)
CVE: CVE-2019-19965
CVE: CVE-2019-19965
Id:
CVE-2019-19965
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19965
Comment
: In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.7
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f70267f379b5e5e11bdc5d72a56bf17e5feed01f (MISC)
[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update (MLIST)
https://security.netapp.com/advisory/ntap-20200204-0002/ (CONFIRM)
USN-4285-1 (UBUNTU)
USN-4287-1 (UBUNTU)
USN-4286-2 (UBUNTU)
USN-4287-2 (UBUNTU)
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update (MLIST)
USN-4284-1 (UBUNTU)
USN-4286-1 (UBUNTU)
openSUSE-SU-2020:0336 (SUSE)
CVE: CVE-2019-20054
CVE: CVE-2019-20054
Id:
CVE-2019-20054
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20054
Comment
: In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links, aka CID-23da9588037e.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=23da9588037ecdd4901db76a5b79a42b529c4ec3 (MISC)
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.6 (MISC)
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.11 (MISC)
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=89189557b47b35683a27c80ee78aef18248eefb4 (MISC)
https://security.netapp.com/advisory/ntap-20200204-0002/ (CONFIRM)
openSUSE-SU-2020:0336 (SUSE)
CVE: CVE-2019-20096
CVE: CVE-2019-20096
Id:
CVE-2019-20096
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20096
Comment
: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
401 (Improper Release of Memory Before Removing Last Reference ('Memory Leak'))
References:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1 (MISC)
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1d3ff0950e2b40dc861b1739029649d03f591820 (MISC)
http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LSN-0063-1.html (MISC)
USN-4285-1 (UBUNTU)
USN-4287-1 (UBUNTU)
USN-4286-2 (UBUNTU)
USN-4287-2 (UBUNTU)
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update (MLIST)
USN-4286-1 (UBUNTU)
openSUSE-SU-2020:0336 (SUSE)
CVE: CVE-2019-19966
CVE: CVE-2019-19966
Id:
CVE-2019-19966
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19966
Comment
: In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
416 (Use After Free)
References:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=dea37a97265588da604c6ba80160a287b72c7bfd (MISC)
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.6 (MISC)
[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update (MLIST)
https://security.netapp.com/advisory/ntap-20200204-0002/ (CONFIRM)
openSUSE-SU-2020:0336 (SUSE)
CVE: CVE-2019-19447
CVE: CVE-2019-19447
Id:
CVE-2019-19447
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19447
Comment
: In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.
CVSSv2 Score:
6.8
Access vector:
NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19447 (MISC)
https://security.netapp.com/advisory/ntap-20200103-0001/ (CONFIRM)
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update (MLIST)
openSUSE-SU-2020:0336 (SUSE)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
CVE: CVE-2019-19319
CVE: CVE-2019-19319
Id:
CVE-2019-19319
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19319
Comment
: In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, aka CID-345c0dbf3a30.
CVSSv2 Score:
4.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P
CVSSv3 Score:
6.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19319 (MISC)
https://security.netapp.com/advisory/ntap-20200103-0001/ (CONFIRM)
openSUSE-SU-2020:0336 (SUSE)
[debian-lts-announce] 20200609 [SECURITY] [DLA 2241-1] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2241-2] linux security update (MLIST)
[debian-lts-announce] 20200610 [SECURITY] [DLA 2242-1] linux-4.9 security update (MLIST)
DSA-4698 (DEBIAN)
USN-4391-1 (UBUNTU)
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=345c0dbf3a30 (CONFIRM)
https://bugzilla.suse.com/show_bug.cgi?id=1158021 (MISC)
CVE: CVE-2019-19767
CVE: CVE-2019-19767
Id:
CVE-2019-19767
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19767
Comment
: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVSSv2 Score:
4.3
Access vector:
NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE:
416 (Use After Free)
References:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.2 (MISC)
https://github.com/torvalds/linux/commit/4ea99936a1630f51fc3a2d61a58ec4a1c4b7d55a (MISC)
https://bugzilla.kernel.org/show_bug.cgi?id=205609 (MISC)
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4ea99936a1630f51fc3a2d61a58ec4a1c4b7d55a (MISC)
https://bugzilla.kernel.org/show_bug.cgi?id=205707 (MISC)
https://security.netapp.com/advisory/ntap-20200103-0001/ (CONFIRM)
[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update (MLIST)
USN-4258-1 (UBUNTU)
USN-4287-1 (UBUNTU)
USN-4287-2 (UBUNTU)
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update (MLIST)
USN-4284-1 (UBUNTU)
openSUSE-SU-2020:0336 (SUSE)
CVE: CVE-2019-11091
CVE: CVE-2019-11091
Id:
CVE-2019-11091
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11091
Comment
: Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html (CONFIRM)
openSUSE-SU-2019:1505 (SUSE)
RHSA-2019:1455 (REDHAT)
USN-3977-3 (UBUNTU)
[debian-lts-announce] 20190620 [SECURITY] [DLA 1789-2] intel-microcode security update (MLIST)
20190624 [SECURITY] [DSA 4447-2] intel-microcode security update (BUGTRAQ)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-616472.pdf (CONFIRM)
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190712-01-mds-en (CONFIRM)
openSUSE-SU-2019:1806 (SUSE)
openSUSE-SU-2019:1805 (SUSE)
FreeBSD-SA-19:07 (FREEBSD)
RHSA-2019:2553 (REDHAT)
https://kc.mcafee.com/corporate/index?page=content&id=SB10292 (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
20191112 [SECURITY] [DSA 4564-1] linux security update (BUGTRAQ)
https://www.synology.com/security/advisory/Synology_SA_19_24 (CONFIRM)
DSA-4602 (DEBIAN)
20200114 [SECURITY] [DSA 4602-1] xen security update (BUGTRAQ)
GLSA-202003-56 (GENTOO)
FEDORA-2019-1f5832fc0e ()
CVE: CVE-2018-12126
CVE: CVE-2018-12126
Id:
CVE-2018-12126
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12126
Comment
: Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html (CONFIRM)
openSUSE-SU-2019:1505 (SUSE)
RHSA-2019:1455 (REDHAT)
USN-3977-3 (UBUNTU)
[debian-lts-announce] 20190620 [SECURITY] [DLA 1789-2] intel-microcode security update (MLIST)
20190624 [SECURITY] [DSA 4447-2] intel-microcode security update (BUGTRAQ)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-616472.pdf (CONFIRM)
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190712-01-mds-en (CONFIRM)
openSUSE-SU-2019:1806 (SUSE)
openSUSE-SU-2019:1805 (SUSE)
FreeBSD-SA-19:07 (FREEBSD)
RHSA-2019:2553 (REDHAT)
https://kc.mcafee.com/corporate/index?page=content&id=SB10292 (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
FreeBSD-SA-19:26 (FREEBSD)
20191112 FreeBSD Security Advisory FreeBSD-SA-19:26.mcu (BUGTRAQ)
20191112 [SECURITY] [DSA 4564-1] linux security update (BUGTRAQ)
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html (MISC)
https://www.synology.com/security/advisory/Synology_SA_19_24 (CONFIRM)
DSA-4602 (DEBIAN)
20200114 [SECURITY] [DSA 4602-1] xen security update (BUGTRAQ)
GLSA-202003-56 (GENTOO)
FEDORA-2019-1f5832fc0e ()
CVE: CVE-2018-12130
CVE: CVE-2018-12130
Id:
CVE-2018-12130
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12130
Comment
: Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html (CONFIRM)
openSUSE-SU-2019:1505 (SUSE)
RHSA-2019:1455 (REDHAT)
USN-3977-3 (UBUNTU)
[debian-lts-announce] 20190620 [SECURITY] [DLA 1789-2] intel-microcode security update (MLIST)
20190624 [SECURITY] [DSA 4447-2] intel-microcode security update (BUGTRAQ)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-616472.pdf (CONFIRM)
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190712-01-mds-en (CONFIRM)
openSUSE-SU-2019:1806 (SUSE)
openSUSE-SU-2019:1805 (SUSE)
FreeBSD-SA-19:07 (FREEBSD)
RHSA-2019:2553 (REDHAT)
https://kc.mcafee.com/corporate/index?page=content&id=SB10292 (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
FreeBSD-SA-19:26 (FREEBSD)
20191112 FreeBSD Security Advisory FreeBSD-SA-19:26.mcu (BUGTRAQ)
20191112 [SECURITY] [DSA 4564-1] linux security update (BUGTRAQ)
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html (MISC)
https://www.synology.com/security/advisory/Synology_SA_19_24 (CONFIRM)
DSA-4602 (DEBIAN)
20200114 [SECURITY] [DSA 4602-1] xen security update (BUGTRAQ)
GLSA-202003-56 (GENTOO)
FEDORA-2019-1f5832fc0e ()
CVE: CVE-2018-12127
CVE: CVE-2018-12127
Id:
CVE-2018-12127
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12127
Comment
: Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html (CONFIRM)
openSUSE-SU-2019:1505 (SUSE)
RHSA-2019:1455 (REDHAT)
USN-3977-3 (UBUNTU)
[debian-lts-announce] 20190620 [SECURITY] [DLA 1789-2] intel-microcode security update (MLIST)
20190624 [SECURITY] [DSA 4447-2] intel-microcode security update (BUGTRAQ)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-616472.pdf (CONFIRM)
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190712-01-mds-en (CONFIRM)
openSUSE-SU-2019:1806 (SUSE)
openSUSE-SU-2019:1805 (SUSE)
FreeBSD-SA-19:07 (FREEBSD)
RHSA-2019:2553 (REDHAT)
https://kc.mcafee.com/corporate/index?page=content&id=SB10292 (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
FreeBSD-SA-19:26 (FREEBSD)
20191112 FreeBSD Security Advisory FreeBSD-SA-19:26.mcu (BUGTRAQ)
20191112 [SECURITY] [DSA 4564-1] linux security update (BUGTRAQ)
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html (MISC)
https://www.synology.com/security/advisory/Synology_SA_19_24 (CONFIRM)
DSA-4602 (DEBIAN)
20200114 [SECURITY] [DSA 4602-1] xen security update (BUGTRAQ)
GLSA-202003-56 (GENTOO)
FEDORA-2019-1f5832fc0e ()
Content available only for registered users!
ovaldb@altx-soft.com