View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2019-15902 severity moderate: SUSE including 297 source package names (cluster-md-kmp-default-4.12.14-120.1, cluster-md-kmp-default-4.12.14-150.35.1, …), 586 product×package rows across 71 product lines (HPE Helion OpenStack 8, SUSE CaaS Platform 3.0, … (71 product lines)): Fixed 554, Known Not Affected 32.
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.