CVE-2019-5489

The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
linuxlinux_kernel
𝑥
≤ 4.19.13
netappactive_iq_performance_analytics_services
-
netappelement_software_management_node
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.226-1
fixed
bookworm
6.1.106-3
fixed
bookworm (security)
6.1.112-1
fixed
trixie
6.11.5-1
fixed
sid
6.11.6-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
eoan
not-affected
disco
Fixed 5.0.0-25.26
released
cosmic
ignored
bionic
Fixed 4.15.0-60.67
released
xenial
Fixed 4.4.0-157.185
released
trusty
ignored
linux-aws
eoan
not-affected
disco
ignored
cosmic
ignored
bionic
Fixed 4.15.0-1047.49
released
xenial
Fixed 4.4.0-1090.101
released
trusty
ignored
linux-aws-5.0
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-aws-hwe
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
Fixed 4.15.0-1047.49~16.04.1
released
trusty
dne
linux-azure
eoan
not-affected
disco
Fixed 5.0.0-1014.14
released
cosmic
ignored
bionic
Fixed 5.0.0-1014.14~18.04.1
released
xenial
Fixed 4.15.0-1056.61
released
trusty
ignored
linux-azure-5.3
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-azure-edge
eoan
dne
disco
dne
cosmic
dne
bionic
Fixed 5.0.0-1014.14~18.04.1
released
xenial
Fixed 4.15.0-1056.61
released
trusty
dne
linux-euclid
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-flo
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-gcp
eoan
not-affected
disco
Fixed 5.0.0-1013.13
released
cosmic
ignored
bionic
Fixed 4.15.0-1042.45
released
xenial
Fixed 4.15.0-1041.43
released
trusty
dne
linux-gcp-5.3
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-gcp-edge
eoan
dne
disco
dne
cosmic
dne
bionic
Fixed 4.15.0-1042.45
released
xenial
dne
trusty
dne
linux-gke
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-gke-4.15
eoan
dne
disco
dne
bionic
Fixed 4.15.0-1041.43
released
xenial
dne
trusty
dne
linux-gke-5.0
eoan
dne
disco
dne
bionic
Fixed 5.0.0-1013.13~18.04.1
released
xenial
dne
trusty
dne
linux-goldfish
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-grouper
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-hwe
eoan
dne
disco
dne
cosmic
dne
bionic
Fixed 5.0.0-25.26~18.04.1
released
xenial
Fixed 4.15.0-60.67~16.04.1
released
trusty
dne
linux-hwe-edge
eoan
dne
disco
dne
cosmic
dne
bionic
ignored
xenial
Fixed 4.15.0-60.67~16.04.1
released
trusty
dne
linux-kvm
eoan
not-affected
disco
Fixed 5.0.0-1013.14
released
cosmic
ignored
bionic
Fixed 4.15.0-1043.43
released
xenial
Fixed 4.4.0-1052.59
released
trusty
dne
linux-lts-trusty
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-lts-utopic
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
ignored
linux-lts-vivid
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
ignored
linux-lts-wily
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
ignored
linux-lts-xenial
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
ignored
linux-maguro
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-mako
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-manta
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-oem
eoan
Fixed 4.15.0-1059.68
released
disco
ignored
cosmic
ignored
bionic
Fixed 4.15.0-1056.65
released
xenial
ignored
trusty
dne
linux-oem-5.4
eoan
dne
bionic
dne
xenial
dne
trusty
dne
linux-oem-osp1
eoan
Fixed 5.0.0-1018.20
released
disco
ignored
bionic
Fixed 5.0.0-1018.20
released
xenial
dne
trusty
dne
linux-oracle
eoan
not-affected
disco
Fixed 5.0.0-1004.8
released
cosmic
ignored
bionic
Fixed 4.15.0-1022.25
released
xenial
Fixed 4.15.0-1022.25~16.04.1
released
trusty
dne
linux-oracle-5.0
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-raspi2
eoan
not-affected
disco
ignored
cosmic
ignored
bionic
Fixed 4.15.0-1044.47
released
xenial
Fixed 4.4.0-1117.126
released
trusty
dne
linux-raspi2-5.3
eoan
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-snapdragon
eoan
dne
disco
Fixed 5.0.0-1018.19
released
cosmic
dne
bionic
Fixed 4.15.0-1062.69
released
xenial
Fixed 4.4.0-1121.127
released
trusty
dne
References