Description
The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1823-1 | linux security update |
Debian DLA |
DLA-1824-1 | linux-4.9 security update |
Debian DSA |
DSA-4465-1 | linux security update |
EUVD |
EUVD-2019-15064 | The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server. |
References
History
No history.
Subscriptions
Linux
Subscribe
Linux Kernel
Subscribe
Netapp
Subscribe
Active Iq Performance Analytics Services
Subscribe
Element Software Management Node
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Mrg
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Els
Subscribe
Rhel Eus
Subscribe
Rhel Extras Rt
Subscribe
Rhel Tus
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T19:54:53.490Z
Reserved: 2019-01-07T00:00:00.000Z
Link: CVE-2019-5489
No data.
Status : Modified
Published: 2019-01-07T17:29:00.470
Modified: 2024-11-21T04:45:02.283
Link: CVE-2019-5489
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD