VulnerabilityModified
CVE-2002-1571
The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.
LOW 2.1EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://linux.bkbits.net:8080/linux-2.4/diffs/arch/i386/kernel/i387.c%401.6
- http://search.luky.org/linux-kernel.2002/msg24003.html
- http://search.luky.org/linux-kernel.2002/msg24992.html
- http://www.cs.helsinki.fi/linux/linux-kernel/2002-15/0628.html
- http://www.cs.helsinki.fi/linux/linux-kernel/2002-15/0760.html
- http://linux.bkbits.net:8080/linux-2.4/diffs/arch/i386/kernel/i387.c%401.6
- http://search.luky.org/linux-kernel.2002/msg24003.html
- http://search.luky.org/linux-kernel.2002/msg24992.html
- http://www.cs.helsinki.fi/linux/linux-kernel/2002-15/0628.html
- http://www.cs.helsinki.fi/linux/linux-kernel/2002-15/0760.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.