CVE-2012-4508
published 2012-12-21CVE-2012-4508: Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an…
PriorityP45low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.29%
20.8th percentile
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.35-1 (bookworm) | linux 3.2.35-1 (bookworm) |
| linux | linux_kernel | <= 3.4.15 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_ubuntu4.9MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-07-04·CVSS 1.9
CVE-2012-4508 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Dave Jones discovered that the Linux kernel's socket subsystem does not
correctly ensure the keepalive action is associated with a stream socket. A
local user could exploit this flaw to cause a denial of service (system
crash) by creating a raw socket. (CVE-2012-6657)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
Kees Cook di
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-07-04·CVSS 1.9
CVE-2012-4508 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Dave Jones discovered that the Linux kernel's socket subsystem does not
correctly ensure the keepalive action is associated with a stream socket. A
local user could exploit this flaw to cause a denial of service (system
crash) by creating a raw socket. (CVE-2012-6657)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
Kees Cook discover
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-02-14·CVSS 2.1
CVE-2012-2669 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that hypervkvpd, which is distributed in the Linux
kernel, was not correctly validating the origin on Netlink messages. An
untrusted local user can cause a denial of service of Linux guests in
Hyper-V virtualization environments. (CVE-2012-2669)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Florian Weimer discovered that hypervkvpd, which is distributed in the
Linux kernel, was not correctly validating source addresses of netlink
packets. An untrusted local user can cause a denial of service by causing
hypervkvpd to exit. (
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2013-02-12·CVSS 2.1
CVE-2012-2669 [LOW] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that hypervkvpd, which is distributed in the Linux
kernel, was not correctly validating the origin on Netlink messages. An
untrusted local user can cause a denial of service of Linux guests in
Hyper-V virtualization environments. (CVE-2012-2669)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
Instructions: After a stand
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-02-12·CVSS 2.1
CVE-2012-2669 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that hypervkvpd, which is distributed in the Linux
kernel, was not correctly validating the origin on Netlink messages. An
untrusted local user can cause a denial of service of Linux guests in
Hyper-V virtualization environments. (CVE-2012-2669)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Florian Weimer discovered that hypervkvpd, which is distributed in the
Linux kernel, was not correctly validating source addresses of netlink
packets. An untrusted local user can cause a denial of service by causing
hypervkvpd to exit. (CVE-2012
Ubuntu
Linux kernel (Quantal HWE) regression
vendor_ubuntu·2013-02-01·CVSS 4.9
[MEDIUM] Linux kernel (Quantal HWE) regression
Title: Linux kernel (Quantal HWE) regression
Summary: USN-1704-1 introduced a regression in the Linux kernel.
USN-1704-1 fixed vulnerabilities in the Linux kernel. Due to an unrelated
regression inotify/fanotify stopped working after upgrading. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Jon Howell reported a flaw in the Linux kernel's KVM (Kernel-based virtual
machine) subsystem's handling of the XSAVE feature. On hosts, using qemu
userspace, without the XSAVE feature an unprivileged local attacker could
exploit this flaw to crash the system. (CVE-2012-4461)
Dmitry Monakho
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-01-22·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Jon Howell reported a flaw in the Linux kernel's KVM (Kernel-based virtual
machine) subsystem's handling of the XSAVE feature. On hosts, using qemu
userspace, without the XSAVE feature an unprivileged local attacker could
exploit this flaw to crash the system. (CVE-2012-4461)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
A flaw was discovered in the Linux kernel's handling o
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-12-19·CVSS 1.9
CVE-2012-4508 [LOW] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
A flaw was discovered in the Linux kernel's handling of new hot-plugged
memory. An unprivileged local user could exploit this flaw to cause a
denial of service by crashing the system. (CVE-2012-5517)
An information leak was discovered in the Linux kernel's /dev/dvb device. A
local user could exploit this flaw to obtain sensitive information from the
kernel's stack memory. (CVE-2013-1928)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary chang
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-12-19·CVSS 1.9
CVE-2012-4508 [LOW] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash under certain conditions.
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
A flaw was discovered in the Linux kernel's handling of new hot-plugged
memory. An unprivileged local user could exploit this flaw to cause a
denial of service by crashing the system. (CVE-2012-5517)
An information leak was discovered in the Linux kernel's /dev/dvb device. A
local user could exploit this flaw to obtain sensitive information from the
kernel's stack memory. (CVE-2013-1928)
Instructions: After a standard system update you need to reboot your computer to make
all the necessa
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the contents of
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the con
Red Hat
kernel: ext4: AIO vs fallocate stale data exposure
vendor_redhat·2012-10-23·CVSS 1.9
CVE-2012-4508 [LOW] kernel: ext4: AIO vs fallocate stale data exposure
kernel: ext4: AIO vs fallocate stale data exposure
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.
Debian
CVE-2012-4508: linux - Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows loc...
vendor_debian·2012·CVSS 1.9
CVE-2012-4508 [LOW] CVE-2012-4508: linux - Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows loc...
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.
Scope: local
bookworm: resolved (fixed in 3.2.35-1)
bullseye: resolved (fixed in 3.2.35-1)
forky: resolved (fixed in 3.2.35-1)
sid: resolved (fixed in 3.2.35-1)
trixie: resolved (fixed in 3.2.35-1)
GHSA
GHSA-47f6-7g86-xcqc: Race condition in fs/ext4/extents
ghsa_unreviewed·2022-05-17
CVE-2012-4508 [LOW] CWE-362 GHSA-47f6-7g86-xcqc: Race condition in fs/ext4/extents
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.
OSV
CVE-2012-4508: Race condition in fs/ext4/extents
osv·2012-12-21·CVSS 1.9
CVE-2012-4508 [LOW] CVE-2012-4508: Race condition in fs/ext4/extents
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.
Kernel
Merge tag 'ext4_for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4
kernel_security·2012-10-23·CVSS 1.9
CVE-2012-4508 [LOW] Merge tag 'ext4_for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4
Merge tag 'ext4_for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4
Pull ext4 fixes from Ted Ts'o:
"Various bug fixes for ext4. The most serious of them fixes a security
bug (CVE-2012-4508) which leads to stale data exposure when we have
fallocate racing against writes to files undergoing delayed
allocation. We also have two fixes for the metadata checksum feature,
the most serious of which can cause the superblock to have a invalid
checksum after a power failure."
* tag 'ext4_for_linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4:
ext4: Avoid underflow in ext4_trim_fs()
ext4: Checksum the block bitmap properly with bigalloc enabled
ext4: fix undefined bit shift result in ext4_fill_flex_info
ext4: fix metadata checksum calculation for the superblock
ext
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4508 kernel: ext4: AIO vs fallocate stale data exposure
bugzilla·2012-10-25·CVSS 1.9
CVE-2012-4508 [LOW] CVE-2012-4508 kernel: ext4: AIO vs fallocate stale data exposure
CVE-2012-4508 kernel: ext4: AIO vs fallocate stale data exposure
A race condition flaw has been found in the way asynchronous I/O and fallocate interacted which can lead to exposure of stale data -- that is, an extent which should have had the "uninitialized" bit set indicating that its blocks have not yet been written and thus contain data from a deleted file. An unprivileged local user could use this flaw to cause an information leak.
Acknowledgements:
Red Hat would like to thank Theodore Ts'o for reporting this issue. Upstream acknowledges Dmitry Monakhov as the original reporter.
References:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=dee1f973ca341c266229faa5a1a5bb268bed3531
Discussion:
Created attachment 633181
Upstream patches
Theodore Ts'o
Bugzilla
CVE-2012-4508 kernel: ext4: AIO vs fallocate stale data exposure [fedora-all]
bugzilla·2012-10-25·CVSS 1.9
CVE-2012-4508 [LOW] CVE-2012-4508 kernel: ext4: AIO vs fallocate stale data exposure [fedora-all]
CVE-2012-4508 kernel: ext4: AIO vs fallocate stale data exposure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=dee1f973ca341c266229faa5a1a5bb268bed3531http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091110.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1540.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0496.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1519.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1783.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.16http://www.openwall.com/lists/oss-security/2012/10/25/1http://www.ubuntu.com/usn/USN-1645-1http://www.ubuntu.com/usn/USN-1899-1http://www.ubuntu.com/usn/USN-1900-1https://bugzilla.redhat.com/show_bug.cgi?id=869904https://github.com/torvalds/linux/commit/dee1f973ca341c266229faa5a1a5bb268bed3531https://www.suse.com/support/update/announcement/2012/suse-su-20121679-1.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=dee1f973ca341c266229faa5a1a5bb268bed3531http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091110.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1540.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0496.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1519.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1783.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.16http://www.openwall.com/lists/oss-security/2012/10/25/1http://www.ubuntu.com/usn/USN-1645-1http://www.ubuntu.com/usn/USN-1899-1http://www.ubuntu.com/usn/USN-1900-1https://bugzilla.redhat.com/show_bug.cgi?id=869904https://github.com/torvalds/linux/commit/dee1f973ca341c266229faa5a1a5bb268bed3531https://www.suse.com/support/update/announcement/2012/suse-su-20121679-1.html
2012-12-21
Published