VDB
ALINUX2-SA-2020%3A0018
ALINUX2-SA-2020%3A0018
PUBLISHED
CVSS 6.5 MEDIUM
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. CVE-2019-14378: ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.
Risk Scores
CVSS 3.0
6.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | qemu-kvm |
Timeline
- Feb 6, 2020 CVE Published
- Feb 6, 2020 CVE Updated