Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
SaketADumbre committed Dec 12, 2024
1 parent 947c9fa commit 1990c1c
Showing 1 changed file with 24 additions and 2 deletions.
Original file line number Diff line number Diff line change
@@ -1,24 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc4x-9vpx-cphw",
"modified": "2022-05-17T00:52:43Z",
"modified": "2023-02-03T05:02:43Z",
"published": "2022-05-17T00:52:43Z",
"aliases": [
"CVE-2017-13694"
],
"summary": "Fix this CVE after merging ACPICA PR #278",
"details": "The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": ""
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13694"
},
{
"type": "PACKAGE",
"url": "https://github.com/acpica/acpica/pull/278"
},
{
"type": "WEB",
"url": "https://github.com/acpica/acpica/pull/278/commits/4a0243ecb4c94e2d73510d096c5ea4d0711fc6c0"
Expand Down

0 comments on commit 1990c1c

Please sign in to comment.