USN-4096-1: Linux kernel (AWS) vulnerability
Andrei Vlad Lutas and Dan Lutas discovered that some x86 processors incorrectly handle SWAPGS instructions during speculative execution. A local attacker could use this to expose sensitive information (kernel memory).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Linux kernel (AWS) vulnerability?
The vulnerability ID for this Linux kernel (AWS) vulnerability is USN-4096-1.
How does the vulnerability affect the Linux kernel?
The vulnerability affects some x86 processors and can be used by a local attacker to expose sensitive information in the kernel memory.
Which software versions are affected by this vulnerability?
The following software versions are affected: - Ubuntu Ubuntu 19.04 with linux-image-5.0.0-1012-aws (up to version 5.0.0-1012.13) - Ubuntu Ubuntu 19.04 with linux-image-aws (up to version 5.0.0.1012.12) - Ubuntu Ubuntu 18.04 with linux-image-4.15.0-1045-aws (up to version 4.15.0-1045.47) - Ubuntu Ubuntu 18.04 with linux-image-aws (up to version 4.15.0.1045.44) - Ubuntu Ubuntu 16.04 with linux-image-4.15.0-1045-aws (up to version 4.15.0-1045.47~16.04.1) - Ubuntu Ubuntu 16.04 with linux-image-aws-hwe (up to version 4.15.0.1045.45)
How can I fix this vulnerability?
To fix the vulnerability, you should update your Linux kernel to the recommended versions: - For Ubuntu 19.04, update to linux-image-5.0.0-1012-aws version 5.0.0-1012.13. - For Ubuntu 18.04, update to linux-image-4.15.0-1045-aws version 4.15.0-1045.47. - For Ubuntu 16.04, update to linux-image-4.15.0-1045-aws version 4.15.0-1045.47~16.04.1 or linux-image-aws-hwe version 4.15.0.1045.45.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the following references: - [CVE-2019-1125](https://ubuntu.com/security/CVE-2019-1125) - [USN-4095-1](https://ubuntu.com/security/notices/USN-4095-1) - [USN-4094-1](https://ubuntu.com/security/notices/USN-4094-1)