fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases on amd64, aka CID-59c4bd853abc.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade kernel-tools-libs-devel | May 4, 2022 | Dec 5, 2019 |
| Amazon Linux Ami 2 | — | Upgrade perf-debuginfoUpgrade python-perf-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade kernel-tools-develUpgrade kernel-debuginfoUpgrade perfUpgrade python-perfUpgrade kernel-develUpgrade kernelUpgrade kernel-toolsUpgrade kernel-debuginfo-common-aarch64 | May 21, 2024 | Dec 5, 2019 |
| Centos_linux | — | Upgrade kernel | Feb 16, 2021 | Dec 5, 2019 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Dec 5, 2019 |
| Oracle_linux | — | Upgrade kernel | Jul 22, 2024 | Nov 26, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Mar 12, 2021 | Dec 5, 2019 |
| Redhat_linux | — | Upgrade kernelNo solution exists | Feb 16, 2021 | Dec 5, 2019 |
| Suse | — | Upgrade kernel-default | Feb 4, 2022 | Dec 5, 2019 |
| Ubuntu | — | Upgrade linux-image-5.3.0-40-genericUpgrade linux-image-5.3.0-40-lowlatencyUpgrade linux-image-snapdragonUpgrade linux-image-virtualUpgrade linux-image-lowlatency-hwe-18.04Upgrade linux-image-raspi2-hwe-18.04Upgrade linux-image-genericUpgrade linux-image-gkeUpgrade linux-image-5.3.0-40-snapdragonUpgrade linux-image-snapdragon-hwe-18.04Upgrade linux-image-lowlatencyUpgrade linux-image-5.3.0-1013-azureUpgrade linux-image-generic-lpaeUpgrade linux-image-5.3.0-1011-awsUpgrade linux-image-5.3.0-1010-kvmUpgrade linux-image-generic-lpae-hwe-18.04Upgrade linux-image-oracleUpgrade linux-image-azure-edgeUpgrade linux-image-azureUpgrade linux-image-kvmUpgrade linux-image-5.3.0-1009-oracleUpgrade linux-image-5.3.0-1012-gcpUpgrade linux-image-5.3.0-40-generic-lpaeUpgrade linux-image-generic-hwe-18.04Upgrade linux-image-5.3.0-1018-raspi2Upgrade linux-image-virtual-hwe-18.04Upgrade linux-image-gcp-edgeUpgrade linux-image-awsUpgrade linux-image-raspi2Upgrade linux-image-gcp | Feb 19, 2020 | Dec 5, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub