kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 4.19.19 |
| linux / linux_kernel | 4.20.0 | 4.20.6 |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 18.04 | 18.04.x |
| canonical / ubuntu_linux | 18.10 | 18.10.x |
| opensuse / leap | 15.0 | 15.0.x |