CVE-2019-15902
Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate.
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.
- CVSS 3.1
- 5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- linux/linux kernel · netapp/active iq performance analytics services · netapp/service processor · debian/debian linux · opensuse/leap · netapp/baseboard management controller firmware
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.htmlThird Party Advisory
- https://grsecurity.net/teardown_of_a_failed_linux_lts_spectre_fix.phpExploit, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00000.htmlThird Party Advisory
- https://seclists.org/bugtraq/2019/Sep/41Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20191004-0001/Third Party Advisory
- https://usn.ubuntu.com/4157-1/
- https://usn.ubuntu.com/4157-2/
- https://usn.ubuntu.com/4162-1/
- https://usn.ubuntu.com/4162-2/
- https://usn.ubuntu.com/4163-1/
- https://usn.ubuntu.com/4163-2/
- https://www.debian.org/security/2019/dsa-4531Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.htmlThird Party Advisory
- https://grsecurity.net/teardown_of_a_failed_linux_lts_spectre_fix.phpExploit, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00000.htmlThird Party Advisory
- https://seclists.org/bugtraq/2019/Sep/41Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20191004-0001/Third Party Advisory
- https://usn.ubuntu.com/4157-1/
- https://usn.ubuntu.com/4157-2/
- https://usn.ubuntu.com/4162-1/
- https://usn.ubuntu.com/4162-2/
- https://usn.ubuntu.com/4163-1/
- https://usn.ubuntu.com/4163-2/
- https://www.debian.org/security/2019/dsa-4531Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.