Back

MEDIUM

kernel: timing side channel vulnerability in the Linux Extended Verification Module

Published Apr 27, 2016

Description

The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4,5 and 6. This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 7 and kernel-rt packages and does not plan to be addressed in a future update.

Metrics

Weaknesses (2)

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 27, 2016
Updated Aug 5, 2024
Reserved Jan 27, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 11, 2016