VDB

ALINUX2-SA-2020%3A0018

ALINUX2-SA-2020%3A0018 PUBLISHED CVSS 6.5 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. CVE-2019-14378: ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

Risk Scores

CVSS 3.0
6.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
Alibaba Cloudqemu-kvm

Timeline

  • Feb 6, 2020 CVE Published
  • Feb 6, 2020 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›