Information disclosure in Linux kernel - CVE-2018-15594

 

Information disclosure in Linux kernel - CVE-2018-15594

Published: August 20, 2018 / Updated: August 22, 2018


Vulnerability identifier: #VU14495
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15594
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to conduct Spectre version 2 (Spectre-v2) attacks.

The vulnerability exists in the arch/x86/kernel/paravirt.c source code file due to improper handling of indirect calls to CALLEE_SAVE paravirtual functions. A remote attacker can access the system and execute an application that submits malicious input to access sensitive information, which could be used to conduct additional attacks. 


Affected software

Linux kernel
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time

kernel (Red Hat package)
kernel-rt (Red Hat package)
Red Hat Virtualization Host

How to mitigate CVE-2018-15594

Update to version 4.18.1.

Linux kernel - update to 4.18.1
kernel (Red Hat package) - update to 3.10.0-1062.el7
kernel-rt (Red Hat package) - update to 3.10.0-1062.rt56.1022.el7

External References

Related Security Bulletins