The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/johnsonwangqize/cve-linux/blob/master/%20CVE-2018-5953.md | third party advisory |
http://www.securityfocus.com/bid/105045 | vdb entry third party advisory |
https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html | third party advisory mailing list |
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7d63fb3af87aa67aa7d24466e792f9d7c57d8e79 | patch vendor advisory |