Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20240
HistoryMay 16, 2019 - 4:01 a.m.

Information Disclosure

2019-05-1604:01:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.001

Percentile

33.3%

The kernel packages is vulnerable to information disclosure. Microprocessors use a €˜load port€™ subcomponent to perform load operations from memory or IO. During a load operation, the load port receives data from the memory or IO subsystem and then provides the data to the CPU registers and operations in the CPU€™s pipelines. Stale load operations results are stored in the ‘load port’ table until overwritten by newer operations. Certain load-port operations triggered by an attacker can be used to reveal data about previous stale requests leaking data back to the attacker via a timing side-channel.