cbcvebase.
CVE-2019-18660
published 2019-11-27

CVE-2019-18660: The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka…

PriorityP421medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.74%
50.9th percentile
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.

Affected

19 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 5.3.15-1 (bookworm)linux 5.3.15-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel< 5.4.15.4.1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 4.4.0-171.2004.4.0-171.200
linuxlinux_kernel>= 0 < 4.15.0-74.844.15.0-74.84
opensuseleap
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.