The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
[
{
"target": {
"function": "setup_count_cache_flush",
"file": "arch/powerpc/kernel/security.c"
},
"id": "CVE-2019-18660-2a64107d",
"deprecated": false,
"digest": {
"length": 295.0,
"function_hash": "328999111344095524617988556056576831770"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@39e72bf96f5847ba87cc5bd7a3ce0fed813dc9ad",
"signature_version": "v1"
},
{
"target": {
"file": "arch/powerpc/kernel/security.c"
},
"id": "CVE-2019-18660-45f7ceec",
"deprecated": false,
"digest": {
"line_hashes": [
"281755479067083298331353624826771570339",
"113538653264361960737809527832458557187",
"278744692777749366481413989018763899547",
"169010183182333967990033672134899567691",
"235461007612216042327332462857389948462",
"147353399551411014500167082735533816362",
"228560351845642232213192465157410851155",
"311081099405011646775593930271933891025",
"215843710302138142584961351423147403934",
"255421342529134402220279733815916140075",
"164224910272998887804095733324929024589",
"326100002292773275732970855718965549171",
"196509585065076782599280414096442662037",
"51095476047286860440568205557269030154",
"147439223404229716156027867490059697571",
"285611177641245368565441063767057194957",
"168807799867562369383216828003806240617",
"114355884293859169526518161895162765755",
"142488326010964426284823134916858554697",
"103468809114562525962590412071023987622",
"109389859454652932364579361913627053651",
"202718872291232104297507168320246080288",
"291702954146533442310897934786065755479",
"301555702103479879234474843047271123165",
"232866944424263819734471314052986240093",
"339609562935987683148371493032600049379",
"4074032379779563355555931575305943005",
"185125041666342531555075411697180583846",
"68687678910004196819522845721446420869",
"15584798593455861140215509469494059798",
"214343052165967636346910838348261121755"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@39e72bf96f5847ba87cc5bd7a3ce0fed813dc9ad",
"signature_version": "v1"
},
{
"target": {
"function": "toggle_count_cache_flush",
"file": "arch/powerpc/kernel/security.c"
},
"id": "CVE-2019-18660-84f8cf60",
"deprecated": false,
"digest": {
"length": 762.0,
"function_hash": "170694700258633922511215551558318229196"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@39e72bf96f5847ba87cc5bd7a3ce0fed813dc9ad",
"signature_version": "v1"
},
{
"target": {
"function": "cpu_show_spectre_v2",
"file": "arch/powerpc/kernel/security.c"
},
"id": "CVE-2019-18660-bf5c0d6d",
"deprecated": false,
"digest": {
"length": 917.0,
"function_hash": "56388799452458082179899923396826298531"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@39e72bf96f5847ba87cc5bd7a3ce0fed813dc9ad",
"signature_version": "v1"
},
{
"target": {
"file": "arch/powerpc/include/asm/asm-prototypes.h"
},
"id": "CVE-2019-18660-cf9800d8",
"deprecated": false,
"digest": {
"line_hashes": [
"259963331284679410659122354051527138739",
"317033996509362862490038876233498046955",
"240859558916816180505806826822551685741",
"181293300892833377443766348746766197535"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@39e72bf96f5847ba87cc5bd7a3ce0fed813dc9ad",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-18660.json"