Tracker / CVE-2019-15902
CVE-2019-15902
Medium 5.6
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.
Affected products and versions
| debian | debian_linux |
|---|---|
| linux | linux_kernel · 4.14 → 4.14.141 |
| linux | linux_kernel · 4.19 → 4.19.69 |
| linux | linux_kernel · 4.4 → 4.4.190 |
| linux | linux_kernel · 4.9 → 4.9.190 |
| linux | linux_kernel · 5.2 → 5.2.11 |
| netapp | active_iq_performance_analytics_services |
| netapp | baseboard_management_controller_firmware |
| netapp | service_processor |
| opensuse | leap |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.