CVE-2019-15902: Debian Linux

Medium severity, CVSS 5.6. EPSS: 0.6% chance of exploitation in the next 30 days.

A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Linux Linux Kernel: from 4.4, up to and including 4.4.190; from 4.9, up to and including 4.9.190; from 4.14, up to and including 4.14.141; from 4.19, up to and including 4.19.69; from 5.2, up to and including 5.2.11
  • Netapp Active Iq Performance Analytics Services: affected versions not specified
  • Netapp Baseboard Management Controller Firmware: affected versions not specified
  • Netapp Service Processor: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 15.1 only

Published 2019-09-04. Last modified 2026-06-17.