Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2021-26313
HistoryJun 09, 2021 - 12:15 p.m.

CVE-2021-26313

2021-06-0912:15:07
Debian Security Bug Tracker
security-tracker.debian.org
13
speculative code bypass
data leakage
speculative execution
software vulnerabilities
cpu products
unix

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

21.0%

Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.

OSVersionArchitecturePackageVersionFilename
Debian12allxen< 4.14.2+25-gb6a8c4f72d-1xen_4.14.2+25-gb6a8c4f72d-1_all.deb
Debian11allxen< 4.14.2+25-gb6a8c4f72d-1xen_4.14.2+25-gb6a8c4f72d-1_all.deb
Debian999allxen< 4.14.2+25-gb6a8c4f72d-1xen_4.14.2+25-gb6a8c4f72d-1_all.deb
Debian13allxen< 4.14.2+25-gb6a8c4f72d-1xen_4.14.2+25-gb6a8c4f72d-1_all.deb

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

21.0%