4.7
CVSSv2

CVE-2019-15902

Published: 04/09/2019 Updated: 17/10/2019
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.6 | Impact Score: 4 | Exploitability Score: 1.1
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

A backporting error exists in the Linux stable/longterm kernel 4.4.x up to and including 4.4.190, 4.9.x up to and including 4.9.190, 4.14.x up to and including 4.14.141, 4.19.x up to and including 4.19.69, and 5.2.x up to and including 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

debian debian linux 9.0

debian debian linux 10.0

opensuse leap 15.0

opensuse leap 15.1

netapp active iq performance analytics services -

debian debian linux 8.0

netapp service processor -

netapp baseboard_management_controller_firmware -

Vendor Advisories

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks CVE-2019-14821 Matt Delco reported a race condition in KVM's coalesced MMIO facility, which could lead to out-of-bounds access in the kernel A local attacker permitted to access /dev/kvm cou ...
A backporting error was discovered in the Linux stable/longterm kernel 44x through 44190, 49x through 49190, 414x through 414141, 419x through 41969, and 52x through 5211 Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Impact: Moderate Public Date: 2019-09-03 CWE: CWE-416 Bugzilla: 1752081: CVE-2019-15902 kernel: backpor ...