CVE-2019-19602Improper Restriction of Operations within the Bounds of a Memory Buffer in Kernel

Severity
6.1MEDIUMNVD
OSV5.5
EPSS
0.0%
top 90.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 5
Latest updateMay 24

Description

fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases on amd64, aka CID-59c4bd853abc.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:LExploitability: 1.8 | Impact: 4.2

Affected Packages3 packages

NVDlinux/linux_kernel< 5.4.2
Debianlinux/linux_kernel< 5.3.15-1+3
debiandebian/linux< linux 5.3.15-1 (bookworm)

Also affects: Ubuntu Linux 18.04, 19.10

🔴Vulnerability Details

3
GHSA
GHSA-7p3p-c3r9-hpgr: fpregs_state_valid in arch/x86/include/asm/fpu/internal2022-05-24
OSV
linux, linux-aws, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-raspi2-5.3 vulnerabilities2020-02-19
OSV
CVE-2019-19602: fpregs_state_valid in arch/x86/include/asm/fpu/internal2019-12-05

📋Vendor Advisories

3
Ubuntu
Linux kernel vulnerabilities2020-02-19
Red Hat
kernel: cached use of fpu_fpregs_owner_ctx in arch/x86/include/asm/fpu/internal.h can lead to DoS2019-11-26
Debian
CVE-2019-19602: linux - fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel be...2019

📄Research Papers

1
arXiv
TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities2022-01-24

💬Community

2
Bugzilla
CVE-2019-19602 kernel: cached use of fpu_fpregs_owner_ctx in arch/x86/include/asm/fpu/internal.h can lead to DoS [fedora-all]2019-12-17
Bugzilla
CVE-2019-19602 kernel: cached use of fpu_fpregs_owner_ctx in arch/x86/include/asm/fpu/internal.h can lead to DoS2019-12-17