The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-1823-1 | linux security update |
![]() |
DLA-1824-1 | linux-4.9 security update |
![]() |
DSA-4465-1 | linux security update |
![]() |
EUVD-2019-15064 | The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T19:54:53.490Z
Reserved: 2019-01-07T00:00:00
Link: CVE-2019-5489

No data.

Status : Modified
Published: 2019-01-07T17:29:00.470
Modified: 2024-11-21T04:45:02.283
Link: CVE-2019-5489


No data.