fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases on amd64, aka CID-59c4bd853abc.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade kernel-tools-libs-devel | May 4, 2022 | Dec 5, 2019 |
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade kernel-tools-debuginfoUpgrade kernel-debuginfoUpgrade python-perf-debuginfoUpgrade kernel-tools-develUpgrade perf-debuginfoUpgrade kernel-headersUpgrade python-perfUpgrade kernelUpgrade kernel-toolsUpgrade perfUpgrade kernel-develUpgrade kernel-debuginfo-common-aarch64 | May 21, 2024 | Dec 5, 2019 |
| Centos_linux | — | Upgrade kernel | Feb 16, 2021 | Dec 5, 2019 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Dec 5, 2019 |
| Oracle_linux | — | Upgrade kernel | Jul 22, 2024 | Nov 26, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Mar 12, 2021 | Dec 5, 2019 |
| Redhat_linux | — | No solution existsUpgrade kernel | Feb 16, 2021 | Dec 5, 2019 |
| Suse | — | Upgrade kernel-default | Feb 4, 2022 | Dec 5, 2019 |
| Ubuntu | — | Upgrade linux-image-snapdragonUpgrade linux-image-raspi2-hwe-18.04Upgrade linux-image-5.3.0-40-snapdragonUpgrade linux-image-lowlatency-hwe-18.04Upgrade linux-image-5.3.0-40-lowlatencyUpgrade linux-image-5.3.0-1010-kvmUpgrade linux-image-lowlatencyUpgrade linux-image-5.3.0-1011-awsUpgrade linux-image-generic-lpae-hwe-18.04Upgrade linux-image-5.3.0-1013-azureUpgrade linux-image-generic-lpaeUpgrade linux-image-gkeUpgrade linux-image-genericUpgrade linux-image-snapdragon-hwe-18.04Upgrade linux-image-virtualUpgrade linux-image-5.3.0-40-genericUpgrade linux-image-5.3.0-1018-raspi2Upgrade linux-image-5.3.0-1009-oracleUpgrade linux-image-gcp-edgeUpgrade linux-image-oracleUpgrade linux-image-5.3.0-1012-gcpUpgrade linux-image-azureUpgrade linux-image-5.3.0-40-generic-lpaeUpgrade linux-image-azure-edgeUpgrade linux-image-raspi2Upgrade linux-image-virtual-hwe-18.04Upgrade linux-image-awsUpgrade linux-image-gcpUpgrade linux-image-kvmUpgrade linux-image-generic-hwe-18.04 | Feb 19, 2020 | Dec 5, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub