CVE-2019-15902
Summary
| CVE | CVE-2019-15902 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-04 06:15:00 UTC |
| Updated | 2019-10-17 04:15:00 UTC |
| Description | A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Application | Netapp | Active Iq Performance Analytics Services | - | All | All | All |
| Application | Netapp | Active Iq Performance Analytics Services | - | All | All | All |
| Hardware | Netapp | Baseboard Management Controller | - | All | All | All |
| Hardware | Netapp | Baseboard Management Controller | - | All | All | All |
| Operating System | Netapp | Baseboard Management Controller Firmware | - | All | All | All |
| Operating System | Netapp | Baseboard Management Controller Firmware | - | All | All | All |
| Application | Netapp | Service Processor | - | All | All | All |
| Application | Netapp | Service Processor | - | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| September 2019 Linux Kernel Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| grsecurity - Teardown of a Failed Linux LTS Spectre Fix | MISC | grsecurity.net | Exploit, Patch, Third Party Advisory |
| USN-4162-2: Linux kernel (Azure) vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| [security-announce] openSUSE-SU-2019:2181-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| USN-4162-1: Linux kernel vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| [security-announce] openSUSE-SU-2019:2173-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| USN-4163-2: Linux kernel (Xenial HWE) vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| USN-4157-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| USN-4163-1: Linux kernel vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| USN-4157-2: Linux kernel (HWE) vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| [SECURITY] [DLA 1940-1] linux-4.9 security update | MLIST | lists.debian.org | Third Party Advisory |
| Debian -- Security Information -- DSA-4531-1 linux | DEBIAN | www.debian.org | Third Party Advisory |
| Bugtraq: [SECURITY] [DSA 4531-1] linux security update | BUGTRAQ | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.