SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-15902

Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate.

MEDIUM 5.6EPSS 0.59%

Does this matter?

Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.

Description

A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.

CVSS 3.1
5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
0.59% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
linux/linux kernel · netapp/active iq performance analytics services · netapp/service processor · debian/debian linux · opensuse/leap · netapp/baseboard management controller firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.