CVE-2018-5953

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.

References

http://www.securityfocus.com/bid/105045

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7d63fb3af87aa67aa7d24466e792f9d7c57d8e79

https://github.com/johnsonwangqize/cve-linux/blob/master/%20CVE-2018-5953.md

https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html

https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html

Details

Source: MITRE

Published: 2018-08-07

Updated: 2021-01-28

Type: CWE-200

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.14.14 (inclusive)

Configuration 2

OR

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
137128OracleVM 3.4 : Unbreakable / etc (OVMSA-2020-0019)NessusOracleVM Local Security Checks
high
135574Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5649)NessusOracle Linux Local Security Checks
medium
135432Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5644)NessusOracle Linux Local Security Checks
medium
135381Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5642)NessusOracle Linux Local Security Checks
medium
124977EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1524)NessusHuawei Local Security Checks
high
123420Debian DLA-1731-2 : linux regression update (Spectre)NessusDebian Local Security Checks
medium