CVE-2019-20908

NameCVE-2019-20908
DescriptionAn issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)stretch4.9.228-1vulnerable
stretch (security)4.9.240-2vulnerable
buster4.19.146-1fixed
buster (security)4.19.152-1fixed
bullseye, sid5.9.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcebuster4.19.132-1
linuxsource(unstable)5.2.6-1

Notes

[stretch] - linux <ignored> (securelevel included but not supported)
https://www.openwall.com/lists/oss-security/2020/06/14/1
Fixed by: https://git.kernel.org/linus/1957a85b0032a81e6482ca4aab883643b8dae06e

Search for package or bug name: Reporting problems