Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20200115-01-PAGECACHE
HistoryJan 15, 2020 - 12:00 a.m.

Security Advisory - Page-Cache Side-Channel Vulnerability

2020-01-1500:00:00
Huawei Technologies
www.huawei.com
109

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

10.2%

There is a vlunerability in the mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13. An attacker could exploit this vulnerability to conduct a page-cache side-channel attack, allowing the attacker to view page-cache access patterns of other processes on the system. A successful exploit could allow the attacker to access sensitive information, which could be used to conduct further attacks. (Vulnerability ID: HWPSIRT-2019-01135)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2019-5489.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-pagecache-en

Affected configurations

Vulners
Node
huaweicornell-al00indRange<9.1.0.321
OR
huaweifigo-l31Match8.0.0.135
OR
huaweifigo-l31Match8.0.0.168
OR
huaweimate_s_firmwareRange<HMA-AL00C00B175
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108
OR
huaweimate_9_proMatch9.0.0.108d
OR
huaweimate_9_proMatch9.0.0.108d
OR
huaweimate_9_proMatch9.0.0.108d
OR
huaweimate_9_proMatch9.0.0.108d
OR
huaweimate_9_proMatch9.0.0.109
OR
huaweimate_9_proMatch9.0.0.109
OR
huaweimate_9_proMatch9.0.0.109
OR
huaweimate_9_proMatch9.0.0.113
OR
huaweimate_9_proMatch9.0.0.114
OR
huaweimate_9_proMatch9.0.0.117
OR
huaweimate_9_proMatch9.0.0.122
OR
huaweimate_9_proMatch9.0.0.122
OR
huaweimate_9_proMatch9.0.0.122
OR
huaweimate_9_proMatch9.0.0.122
OR
huaweimate_9_proMatch9.0.0.122
OR
huaweimate_9_proMatch9.0.0.122
OR
huaweimate_9_proMatch9.0.0.123
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126
OR
huaweimate_9_proMatch9.0.0.126d
OR
huaweimate_9_proMatch9.0.0.126d
OR
huaweimate_9_proMatch9.0.0.127
OR
huaweimate_9_proMatch9.0.0.128
OR
huaweimate_9_proMatch9.0.0.133
OR
huaweimate_9_proMatch9.0.0.134
OR
huaweimate_9_proMatch9.0.0.134
OR
huaweimate_9_proMatch9.0.0.142
OR
huaweimate_9_proMatch9.0.0.146
OR
huaweimate_9_proMatch9.0.0.146
OR
huaweimate_9_proMatch9.0.0.146
OR
huaweimate_9_proMatch9.0.0.146
OR
huaweimate_9_proMatch9.0.0.146
OR
huaweimate_9_proMatch9.0.0.148
OR
huaweimate_9_proMatch9.0.0.149
OR
huaweimate_9_proMatch9.0.0.150
OR
huaweimate_9_proMatch9.0.0.161
OR
huaweimate_9_proMatch9.0.0.167
OR
huaweimate_9_proMatch9.0.0.168
OR
huaweimate_9_proMatch9.0.0.169
OR
huaweimate_9_proMatch9.0.0.169
OR
huaweimate_9_proMatch9.0.0.171
OR
huaweimate_9_proMatch9.0.0.171
OR
huaweimate_9_proMatch9.0.0.172
OR
huaweimate_9_proMatch9.0.0.44h
OR
huaweihuawei_p20Match8.1.0.175
OR
huaweihuawei_y9_2019Match8.2.0.101
OR
huaweihuawei_y9_2019Match8.2.0.103
OR
huaweihuawei_y9_2019Match8.2.0.131
OR
huaweihuawei_y9_2019Match8.2.0.132
OR
huaweihuawei_y9_2019Match8.2.0.134
OR
huaweihuawei_y9_2019Match8.2.0.137
OR
huaweioceanstor_ismMatchv300r006c00spc001
OR
huaweioceanstor_ismMatchv300r006c10
OR
huaweioceanstor_ismMatchv300r006c10spc100
OR
huaweioceanstor_ismMatchv300r006c20
OR
huaweiprinceton-al10dRange<10.0.0.188
OR
huaweismc2.0Matchv600r019c10spc700
OR
huaweismc2.0Matchv600r019c10spc702
OR
huaweisydney-l21Range<9.0.1.164
OR
huaweisydney-l21Range<9.1.0.213
OR
huaweisydney-l21brRange<9.0.1.170
OR
huaweisydney-l22Range<9.1.0.248
OR
huaweisydney-l22brRange<9.1.0.258
OR
huaweisydney-tl00Range<9.1.0.212
OR
huaweisydneym-l01Range<9.1.0.228
OR
huaweisydneym-l01Range<9.1.0.213
OR
huaweisydneym-l01Range<9.1.0.215
OR
huaweisydneym-l01Range<9.1.0.215
OR
huaweisydneym-l21Range<9.1.0.215
OR
huaweisydneym-l21Range<9.1.0.221
OR
huaweisydneym-l22Range<9.0.1.166
OR
huaweisydneym-l22Range<9.1.0.259
OR
huaweisydneym-l23Range<9.1.0.226
OR
huaweitony-al00bRange<9.1.0.216
OR
huaweiyale-l61cRange<10.0.0.187
OR
huaweiimanager_netecoMatchv600r009c00
OR
huaweiimanager_netecoMatchv600r009c10spc200
OR
huaweiimanager_neteco_6000Matchv600r008c10spc300
OR
huaweiimanager_neteco_6000Matchv600r008c20

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

10.2%