The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2019-11-27 15:15
Updated : 2020-01-28 11:47
NVD link : CVE-2019-18660
Mitre link : CVE-2019-18660
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
redhat
- enterprise_linux
fedoraproject
- fedora
canonical
- ubuntu_linux
linux
- linux_kernel
opensuse
- leap