First published: Tue Aug 13 2019(Updated: )
Andrei Vlad Lutas and Dan Lutas discovered that some x86 processors incorrectly handle SWAPGS instructions during speculative execution. A local attacker could use this to expose sensitive information (kernel memory).
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-5.0.0-1012-aws | <5.0.0-1012.13 | 5.0.0-1012.13 |
Ubuntu OpenSSH Client | =19.04 | |
All of | ||
ubuntu/linux-image-aws | <5.0.0.1012.12 | 5.0.0.1012.12 |
Ubuntu OpenSSH Client | =19.04 | |
All of | ||
ubuntu/linux-image-4.15.0-1045-aws | <4.15.0-1045.47 | 4.15.0-1045.47 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/linux-image-aws | <4.15.0.1045.44 | 4.15.0.1045.44 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/linux-image-4.15.0-1045-aws | <4.15.0-1045.47~16.04.1 | 4.15.0-1045.47~16.04.1 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/linux-image-aws-hwe | <4.15.0.1045.45 | 4.15.0.1045.45 |
Ubuntu OpenSSH Client | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Linux kernel (AWS) vulnerability is USN-4096-1.
The vulnerability affects some x86 processors and can be used by a local attacker to expose sensitive information in the kernel memory.
The following software versions are affected: - Ubuntu Ubuntu 19.04 with linux-image-5.0.0-1012-aws (up to version 5.0.0-1012.13) - Ubuntu Ubuntu 19.04 with linux-image-aws (up to version 5.0.0.1012.12) - Ubuntu Ubuntu 18.04 with linux-image-4.15.0-1045-aws (up to version 4.15.0-1045.47) - Ubuntu Ubuntu 18.04 with linux-image-aws (up to version 4.15.0.1045.44) - Ubuntu Ubuntu 16.04 with linux-image-4.15.0-1045-aws (up to version 4.15.0-1045.47~16.04.1) - Ubuntu Ubuntu 16.04 with linux-image-aws-hwe (up to version 4.15.0.1045.45)
To fix the vulnerability, you should update your Linux kernel to the recommended versions: - For Ubuntu 19.04, update to linux-image-5.0.0-1012-aws version 5.0.0-1012.13. - For Ubuntu 18.04, update to linux-image-4.15.0-1045-aws version 4.15.0-1045.47. - For Ubuntu 16.04, update to linux-image-4.15.0-1045-aws version 4.15.0-1045.47~16.04.1 or linux-image-aws-hwe version 4.15.0.1045.45.
You can find more information about this vulnerability on the following references: - [CVE-2019-1125](https://ubuntu.com/security/CVE-2019-1125) - [USN-4095-1](https://ubuntu.com/security/notices/USN-4095-1) - [USN-4094-1](https://ubuntu.com/security/notices/USN-4094-1)