kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-02-01T22:00:00

Updated: 2024-08-04T20:46:45.926Z

Reserved: 2019-02-01T00:00:00

Link: CVE-2019-7308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-02-01T22:29:00.283

Modified: 2024-11-21T04:47:58.557

Link: CVE-2019-7308

cve-icon Redhat

Severity : Important

Publid Date: 2019-01-03T00:00:00Z

Links: CVE-2019-7308 - Bugzilla