Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
’level’ is user space controlled and used to read from an array. Add the missing array_index_nospec() call to prevent speculative execution.
Details
- Affected product:
- AlmaLinux 9.2 ESU , Debian 10 ELS , TuxCare 9.6 ESU
- Affected packages:
- linux @ 4.19.0 (+2 more)