CVE-2018-5995

Aliases:UBUNTU-CVE-2018-5995DEBIAN-CVE-2018-5995
Advisory lineage Upstream: 0 Downstream: 6
Modified
Published: 07 Aug 2018, 18:00
Last modified:05 Aug 2024, 05:47

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.0 (nvd)
EPSS Score
0.41% LOW
0% probability +0.35%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Aug 2018, 18:00
Published
Vulnerability first disclosed
05 Aug 2024, 05:47
Last Modified
Vulnerability information updated

Description

The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.

CVSS Metrics

  • v3.0MEDIUMScore: 5.5CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.41% Percentile: 35%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • debianlinux

    < 4.15.4-1 | < 4.15.4-1 | < 4.15.4-1 | < 4.15.4-1

  • ubuntulinux

    all | < 4.4.0-222.255

  • ubuntulinux-aws

    < 4.4.0-1102.107 | < 4.4.0-1138.152

  • ubuntulinux-azure

    < 4.15.0-1013.13~16.04.2

  • ubuntulinux-gcp

    < 4.15.0-1014.14~16.04.1

  • ubuntulinux-hwe

    < 4.15.0-24.26~16.04.1

  • ubuntulinux-kvm

    < 4.4.0-1103.112

  • ubuntulinux-lts-xenial

    < 4.4.0-222.255~14.04.1

  • ubuntulinux-snapdragon

    < 4.15.0-1053.57

  • linuxlinux_kernel

    ≤ 4.14.14

References (11)