CVE-2018-5750
MEDIUM severity · CVSS 5.5 · Information disclosure
5.5CVSS MEDIUM
Summary
The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)0%
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://patchwork.kernel.org/patch/10174835/ ↗
Additional information
- NVD record
- https://patchwork.kernel.org/patch/10174835/Patch
- http://www.securitytracker.com/id/1040319Advisory
- https://access.redhat.com/errata/RHSA-2018:0676Advisory
- https://access.redhat.com/errata/RHSA-2018:1062Advisory
- https://access.redhat.com/errata/RHSA-2018:2948Advisory
- https://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlAdvisory
- https://usn.ubuntu.com/3631-1/Advisory
- https://usn.ubuntu.com/3631-2/Advisory