VDB
BDU%3A2020-00368
BDU%3A2020-00368
PUBLISHED
CVSS 7.199999809265137 HIGH
Уязвимость функции cpia2_remap_buffer ядра операционной системы Linux, позволяющая нарушителю получить доступ на чтение и запись на физических страницах ядра и повысить свои привилегии
Risk Scores
CVSS 2.0
7.199999809265137
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения | SUSE Linux Enterprise, Linux |
Timeline
- Jan 29, 2020 CVE Published
- Jun 3, 2024 CVE Updated
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18675 url
- https://deshal3v.github.io/blog/kernel-research/mmap_exploitation url
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=be83bbf806822b1b89e0a0f23cd87cddc409e429 url
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/drivers/media/usb/cpia2/cpia2_core.c url
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.16.15 url
- https://lore.kernel.org/lkml/20191108215038.59170-1-omerdeshalev@gmail.com/ url
- https://lore.kernel.org/lkml/20191111114615.GA418224@kroah.com/ url
- https://lore.kernel.org/lkml/20200108161619.7999-1-tiwai@suse.de/ url
- https://nvd.nist.gov/vuln/detail/CVE-2019-18675 url
- https://security.netapp.com/advisory/ntap-20200103-0001/ url
- https://www.cve.org/CVERecord?id=CVE-2019-18675 url
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.49 advisory
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.137 advisory
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.108 advisory
- https://www.suse.com/security/cve/CVE-2019-18675/ advisory