Lucene search

K
redhatcveRedhat.comRH:CVE-2019-7308
HistoryApr 08, 2020 - 10:16 p.m.

CVE-2019-7308

2020-04-0822:16:34
redhat.com
access.redhat.com
9

0.001 Low

EPSS

Percentile

23.6%

A bypass was found for the Spectre v1 hardening in the eBPF engine of the Linux kernel. The code in the kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.