CVE-2019-1125: Windows Kernel Information Disclosure Vulnerability
A Spectre gadget was found in the Linux kernel's implementation of system interrupts. An attacker with local access could use this information to reveal private data through a Spectre like side channel.
Other sources
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). This flaw is a variant on the previous "speculative execution" attack vectors.
A spectre-v1 like side-channel was found on the kernels implementation of system calls where a local user could use branch misprediction to create an observable timing changes which can inadvertently reveal private data.
Note: This flaw affects both Intel x86-64 and AMD Microprocessors. Other non x86 architectures do not have this attack vector available.
Red Hat product security is not aware of a method that an attacker can use this method of attack directly, fixing this flaw as part of the larger speculative execution issues reduces this attack vector if one becomes known.
After installing the updated kernel package, the system will need to be rebooted for the changes to take effect.
Upstream patch set: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a2059825986a1c8143fd6698774fa9d83733bb11
— Red Hat
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073.
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released a security update on July 9, 2019 that addresses the vulnerability through a software change that mitigates how the CPU speculatively accesses memory. Note that this vulnerability does not require a microcode update from your device OEM.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-754.18.2.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-431.96.1.el6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-504.80.2.el6 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.1.1.rt56.1024.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.1.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-327.82.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-514.69.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.58.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-862.43.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.38.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.7.2.rt9.154.el8_0 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.7.2.el8_0 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 1:3.10.0-693.58.1.rt56.652.el6 - Upgrade
Upgrade
redhat/redhat-release-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.2-15.1.el7 - Upgrade
Upgrade
redhat/redhat-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.2-20191022.0.el7_6 - Upgrade
Upgrade
redhat/imgbasedto a version that resolves this vulnerability.Fixed in 0:1.1.10-0.1.el7e - Upgrade
Upgrade
redhat/ovirt-node-ngto a version that resolves this vulnerability.Fixed in 0:4.3.6-0.20190820.0.el7e - Upgrade
Upgrade
redhat/redhat-release-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.3.6-2.el7e - Upgrade
Upgrade
redhat/redhat-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.3.6-20190924.0.el7_7 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-1125?
The severity of CVE-2019-1125 is rated as medium, indicating a moderate risk of information disclosure through a Spectre-like side channel.
How do I fix CVE-2019-1125?
To mitigate CVE-2019-1125, users should upgrade to the recommended kernel versions provided by Red Hat, such as 0:2.6.32-754.18.2.el6 or any version specified in security patches.
What type of attack does CVE-2019-1125 enable?
CVE-2019-1125 allows an attacker with local access to exploit a Spectre gadget to leak sensitive information through side-channel attacks.
Which systems are affected by CVE-2019-1125?
CVE-2019-1125 affects multiple versions of the Linux kernel, specifically those running on Red Hat Enterprise Linux and related distributions.
Is there a workaround for CVE-2019-1125?
While the best solution is to update the kernel, users may temporarily minimize exposure by restricting local access to systems until updates can be applied.