{ "schema_version": "1.4.0", "id": "GHSA-jfjq-mr93-rm2h", "modified": "2024-04-04T01:18:16Z", "published": "2022-05-24T16:50:37Z", "aliases": [ "CVE-2019-1010066" ], "details": "Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: An attacker could exploit a bug in ioctl interface whitelist checking, in order to write to model specific registers, normally a function reserved for the root user. The fixed version is: v1.2.0.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-1010066" }, { "type": "WEB", "url": "https://github.com/LLNL/msr-safe/compare/v1.1.0...v1.2.0" }, { "type": "WEB", "url": "https://www.tldp.org/LDP/lkmpg/2.4/html/x856.html" } ], "database_specific": { "cwe_ids": [ "CWE-269" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-07-18T14:15:00Z" } }