The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server.
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-132a0221",
"target": {
"file": "mm/mincore.c",
"function": "__mincore_unmapped_range"
},
"digest": {
"function_hash": "137532831244730976275225259495954859999",
"length": 448.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-70059f15",
"target": {
"file": "mm/mincore.c",
"function": "mincore_unmapped_range"
},
"digest": {
"function_hash": "1017039105101216687421186327996944941",
"length": 183.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-86a85ef2",
"target": {
"file": "mm/mincore.c"
},
"digest": {
"line_hashes": [
"212963706256973999636000222145871988681",
"47188259370239354702001422889733133105",
"279534358117367935039045744695823982124",
"106549342143417764925368362292395506262",
"93688776870941741416020919030861542543",
"256444910412228404132983652005894910274",
"194364366910702324699691923289775802851",
"35671609684650555213540870698753758495",
"77922088124968378320320580334278350261",
"94424726112070486966410947211212413521",
"311320728027475184028745772058585260237",
"122258352877947970494536658535952232136",
"35501327386666884459565026329885686872",
"94792280036713591080154065467232400111",
"5210120468666314562912604481547892725",
"251034267349052479975293662989643459942",
"95161061248952634009201524671146403323",
"41338731806220174613370431412213286362",
"216233665078324546104752495056955966760",
"57181161006807656587202398213422344910",
"163151448880507747650998897083942236101",
"216217492235476832868836475686887489802",
"76699879027720936021704534602743145522",
"285353692589012901302564839998541645990",
"26004073953878195632004541874678929705",
"47146942015496285118226533487424751951",
"111164783122835096655687693038386855900",
"127904906639453492462964641702008778177",
"177763649382379389794264490198814249658",
"285534625441409254008058829695655619333",
"221425322557609458450308013183676495615",
"220064920824555591883498435783267807183",
"28794939489015178319107743312832905931",
"1058816335592301312899592951090225584",
"258264707391423297498370573320369189797",
"142981863832852657472853046422633234416",
"252302588385704880970544798342594452595",
"88362314914467302280826625959614328601",
"210459128191864428372172198244688800151",
"86691740259023393493958801026472955674",
"335198700733683089186317969984554776229",
"228004726549647638328663545436090912772",
"326690864385511943216971760743871078098",
"330845843383006990789285026860722098871",
"282869781011125282476643207589410447465",
"278700358363056792606024354944675099711",
"162623274361098931167113258946204226754",
"253337421551260969486027789942647329158",
"286424143674940458848907032206775292999",
"198054475759952085453770955718362052413",
"334578984158155371737249739857174603901",
"32341685919686110975525633920002980110",
"34778909097435725182264385232661155401",
"252173335322701078860193052230396788652",
"311504955440762561887368907448324567424",
"328506820201555417379784330239885697630",
"339446562645607239330875473072514886913",
"51603527907539015623958926378099857004",
"7171651657607791846561264177853410073",
"179696638870608008801609014762120446037",
"267291957765379836041465427581102570796",
"123442880178840945344780833907930744716",
"18196520873647622920719795512291499851",
"219654807808173943272430499325454690306",
"270453845589696867061139487149536827915",
"91642682207334477384450861882434592617",
"302878340058905794934641967211483011133",
"231138543189642473535752090809898389332",
"64436635754538415703147199375023485065",
"111144766421440064112033146182001469526",
"29674133012904223304242870071638543553",
"179628341028353453628525065062461610432"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-a879d81d",
"target": {
"file": "mm/mincore.c",
"function": "mincore_page"
},
"digest": {
"function_hash": "176695593746219415679127365451823089926",
"length": 468.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-e030c449",
"target": {
"file": "mm/mincore.c",
"function": "mincore_pte_range"
},
"digest": {
"function_hash": "128191634787216773404511273134523020162",
"length": 1000.0
},
"signature_type": "Function",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5489.json"
[
{
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-443925ed",
"target": {
"file": "mm/mincore.c",
"function": "mincore_pte_range"
},
"digest": {
"function_hash": "128191634787216773404511273134523020162",
"length": 1000.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-47401f6e",
"target": {
"file": "mm/mincore.c",
"function": "mincore_unmapped_range"
},
"digest": {
"function_hash": "1017039105101216687421186327996944941",
"length": 183.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-7a845b80",
"target": {
"file": "mm/mincore.c",
"function": "__mincore_unmapped_range"
},
"digest": {
"function_hash": "137532831244730976275225259495954859999",
"length": 448.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-9a31debd",
"target": {
"file": "mm/mincore.c"
},
"digest": {
"line_hashes": [
"212963706256973999636000222145871988681",
"47188259370239354702001422889733133105",
"279534358117367935039045744695823982124",
"106549342143417764925368362292395506262",
"93688776870941741416020919030861542543",
"256444910412228404132983652005894910274",
"194364366910702324699691923289775802851",
"35671609684650555213540870698753758495",
"77922088124968378320320580334278350261",
"94424726112070486966410947211212413521",
"311320728027475184028745772058585260237",
"122258352877947970494536658535952232136",
"35501327386666884459565026329885686872",
"94792280036713591080154065467232400111",
"5210120468666314562912604481547892725",
"251034267349052479975293662989643459942",
"95161061248952634009201524671146403323",
"41338731806220174613370431412213286362",
"216233665078324546104752495056955966760",
"57181161006807656587202398213422344910",
"163151448880507747650998897083942236101",
"216217492235476832868836475686887489802",
"76699879027720936021704534602743145522",
"285353692589012901302564839998541645990",
"26004073953878195632004541874678929705",
"47146942015496285118226533487424751951",
"111164783122835096655687693038386855900",
"127904906639453492462964641702008778177",
"177763649382379389794264490198814249658",
"285534625441409254008058829695655619333",
"221425322557609458450308013183676495615",
"220064920824555591883498435783267807183",
"28794939489015178319107743312832905931",
"1058816335592301312899592951090225584",
"258264707391423297498370573320369189797",
"142981863832852657472853046422633234416",
"252302588385704880970544798342594452595",
"88362314914467302280826625959614328601",
"210459128191864428372172198244688800151",
"86691740259023393493958801026472955674",
"335198700733683089186317969984554776229",
"228004726549647638328663545436090912772",
"326690864385511943216971760743871078098",
"330845843383006990789285026860722098871",
"282869781011125282476643207589410447465",
"278700358363056792606024354944675099711",
"162623274361098931167113258946204226754",
"253337421551260969486027789942647329158",
"286424143674940458848907032206775292999",
"198054475759952085453770955718362052413",
"334578984158155371737249739857174603901",
"32341685919686110975525633920002980110",
"34778909097435725182264385232661155401",
"252173335322701078860193052230396788652",
"311504955440762561887368907448324567424",
"328506820201555417379784330239885697630",
"339446562645607239330875473072514886913",
"51603527907539015623958926378099857004",
"7171651657607791846561264177853410073",
"179696638870608008801609014762120446037",
"267291957765379836041465427581102570796",
"123442880178840945344780833907930744716",
"18196520873647622920719795512291499851",
"219654807808173943272430499325454690306",
"270453845589696867061139487149536827915",
"91642682207334477384450861882434592617",
"302878340058905794934641967211483011133",
"231138543189642473535752090809898389332",
"64436635754538415703147199375023485065",
"111144766421440064112033146182001469526",
"29674133012904223304242870071638543553",
"179628341028353453628525065062461610432"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/574823bfab82d9d8fa47f422778043fbb4b4f50e",
"id": "CVE-2019-5489-f0ac610f",
"target": {
"file": "mm/mincore.c",
"function": "mincore_page"
},
"digest": {
"function_hash": "176695593746219415679127365451823089926",
"length": 468.0
},
"signature_type": "Function",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5489.json"