In the Linux kernel, the following vulnerability has been resolved: ima: Fix a potential integer overflow in ima_appraise_measurement When the ima-modsig is enabled, the rc passed to evm_verifyxattr() may be negative, which may cause the integer overflow problem.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 3.1 | 5.5 | Medium | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 10 Version 1803 for x64-based Systems |
| Linux | Linux | 10 Version 1803 for ARM64-based Systems |
| Linux | Linux | 2012 R2 (Core installation) |
| Linux | Linux | 2019 (Core installation) |