cbcvebase.
CVE-2019-7308
published 2019-02-01

CVE-2019-7308: kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases…

PriorityP424medium5.6CVSS 3.0
AVLACHPRLUINSCCHINAN
EPSS
0.54%
42.5th percentile
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.19.20-1 (bookworm)linux 4.19.20-1 (bookworm)
linuxlinux_kernel< 4.19.194.19.19
linuxlinux_kernel>= 0 < 4.19.20-14.19.20-1
linuxlinux_kernel>= 0 < 4.19.20-14.19.20-1
linuxlinux_kernel>= 0 < 4.19.20-14.19.20-1
linuxlinux_kernel>= 0 < 4.19.20-14.19.20-1
linuxlinux_kernel>= 0 < 4.15.0-47.504.15.0-47.50
linuxlinux_kernel>= 4.20.0 < 4.20.64.20.6
opensuseleap

CVSS provenance

nvdv3.05.6MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.