A memory disclosure flaw was found in the Linux kernel's versions before 4.18.0-193.el8 in the sysctl subsystem when reading the /proc/sys/kernel/rh_features file. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade kernel-tools-libs-devel | May 4, 2022 | May 27, 2021 |
| Centos_linux | — | Upgrade kernel-rtUpgrade kernel | Nov 5, 2020 | Nov 3, 2020 |
| Oracle_linux | — | Upgrade kernel | Jul 22, 2024 | Jun 15, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Mar 12, 2021 | Mar 12, 2021 |
| Redhat_linux | — | Upgrade kernel-rtUpgrade kernel | Nov 5, 2020 | Nov 3, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub