CVE-2019-11135
Last modified
CVE-2019-11135 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.. EPSS estimates a 3.13% chance of exploitation in the next 30 days.
Description
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 15.1 |
| Fedoraproject | Fedora | 30 |
| Fedoraproject | Fedora | 31 |
| Slackware | Slackware | 14.2 |
| Hp | Apollo 4200 Firmware | < 2.20 |
| Hp | Apollo 2000 Firmware | < 2.20 |
| Hp | Proliant Bl460c Firmware | < 2.20 |
| Hp | Proliant Dl580 Firmware | < 2.20 |
| Hp | Proliant Dl560 Firmware | < 2.20 |
| Hp | Proliant Dl380 Firmware | < 2.20 |
| Hp | Proliant Dl360 Firmware | < 2.20 |
| Hp | Proliant Dl180 Firmware | < 2.20 |
| Hp | Proliant Dl160 Firmware | < 2.20 |
| Hp | Proliant Dl120 Firmware | < 2.20 |
| Hp | Proliant Dl20 Firmware | < 2.10 |
| Hp | Proliant Ml350 Firmware | < 2.20 |
| Hp | Proliant Ml110 Firmware | < 2.20 |
| Hp | Proliant Ml30 Firmware | < 2.10 |
| Hp | Proliant Xl450 Firmware | < 2.20 |
| Hp | Proliant Xl270d Firmware | < 2.20 |
| Hp | Proliant Xl230k Firmware | < 2.20 |
| Hp | Proliant Xl190r Firmware | < 2.20 |
| Hp | Proliant Xl170r Firmware | < 2.20 |
| Hp | Synergy 480 Firmware | < 2.20 |
| Hp | Synergy 660 Firmware | < 2.20 |
| Hp | Proliant E910 Firmware | < 2.20 |
| Intel | Core I7-10510y Firmware | All versions |
| Intel | Core I5-10310y Firmware | All versions |
| Intel | Core I5-10210y Firmware | All versions |
| Intel | Core I5-10110y Firmware | All versions |
| Intel | Core I7-8500y Firmware | All versions |
| Intel | Core I5-8310y Firmware | All versions |
| Intel | Core I5-8210y Firmware | All versions |
| Intel | Core I5-8200y Firmware | All versions |
| Intel | Core M3-8100y Firmware | All versions |
| Intel | Xeon 8253 Firmware | All versions |
| Intel | Xeon 8256 Firmware | All versions |
| Intel | Xeon 8260 Firmware | All versions |
| Intel | Xeon 8260l Firmware | All versions |
| Intel | Xeon 8260m Firmware | All versions |
| Intel | Xeon 8260y Firmware | All versions |
| Intel | Xeon 8268 Firmware | All versions |
| Intel | Xeon 8270 Firmware | All versions |
| Intel | Xeon 8276 Firmware | All versions |
| Intel | Xeon 8276l Firmware | All versions |
| Intel | Xeon 8276m Firmware | All versions |
| Intel | Xeon 8280 Firmware | All versions |
| Intel | Xeon 8280l Firmware | All versions |
| Intel | Xeon 8280m Firmware | All versions |
Showing 50 of 180 affected configurations. See NVD for the full list.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00045.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00046.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00042.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/155375/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlPatch, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/12/10/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/12/10/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/12/11/1Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3936Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0026Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0028Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0204Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0279Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0366Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0555Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0666Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0730Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10306Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00035.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Dec/28Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Nov/26Mailing List, Patch, Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/21Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202003-56Third Party Advisory
- https://usn.ubuntu.com/4186-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4602Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00045.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00046.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00042.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/155375/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlPatch, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/12/10/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/12/10/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/12/11/1Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3936Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0026Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0028Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0204Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0279Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0366Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0555Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0666Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0730Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10306Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00035.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Dec/28Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Nov/26Mailing List, Patch, Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/21Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202003-56Third Party Advisory
- https://usn.ubuntu.com/4186-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4602Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11135?
How severe is CVE-2019-11135?
How do I fix CVE-2019-11135?
Are you affected by CVE-2019-11135?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
