cbcvebase.
CVE-2019-15902
published 2019-09-04

CVE-2019-15902: A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through…

PriorityP425medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.59%
44.6th percentile
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.2.17-1 (bookworm)linux 5.2.17-1 (bookworm)
linuxlinux_kernel>= 0 < 5.2.17-15.2.17-1
linuxlinux_kernel>= 0 < 5.2.17-15.2.17-1
linuxlinux_kernel>= 0 < 5.2.17-15.2.17-1
linuxlinux_kernel>= 0 < 5.2.17-15.2.17-1
linuxlinux_kernel>= 0 < 4.4.0-166.1954.4.0-166.195
linuxlinux_kernel>= 0 < 4.15.0-66.754.15.0-66.75
linuxlinux_kernel4.14 – 4.14.141
linuxlinux_kernel4.19 – 4.19.69
linuxlinux_kernel4.4 – 4.4.190
linuxlinux_kernel4.9 – 4.9.190
linuxlinux_kernel5.2 – 5.2.11
opensuseleap
opensuseleap

CVSS provenance

nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.