Vulnerability Description
Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: An attacker could exploit a bug in ioctl interface whitelist checking, in order to write to model specific registers, normally a function reserved for the root user. The fixed version is: v1.2.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Llnl | Model Specific Registers-Safe | 1.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/LLNL/msr-safe/compare/v1.1.0...v1.2.0PatchThird Party Advisory
- https://www.tldp.org/LDP/lkmpg/2.4/html/x856.htmlExploitThird Party Advisory
- https://github.com/LLNL/msr-safe/compare/v1.1.0...v1.2.0PatchThird Party Advisory
- https://www.tldp.org/LDP/lkmpg/2.4/html/x856.htmlExploitThird Party Advisory
FAQ
What is CVE-2019-1010066?
CVE-2019-1010066 is a vulnerability with a CVSS score of 7.5 (HIGH). Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The...
How severe is CVE-2019-1010066?
CVE-2019-1010066 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1010066?
Check the references section above for vendor advisories and patch information. Affected products include: Llnl Model Specific Registers-Safe.