Skip to main content

Numeric Errors

CVE-2019-7308

Severity Medium
Score 5.6/10

Summary

kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.

  • HIGH
  • LOCAL
  • NONE
  • CHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-189 - Numeric Errors

Weaknesses in this category are related to improper calculation or conversion of numbers.

References

Advisory Timeline

  • Published