CVE-2017-7495
published 2017-05-15CVE-2017-7495: fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users…
PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.40%
33.2th percentile
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.6.2-1 (bookworm) | linux 4.6.2-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 4.6.1 | — |
| linux | linux_kernel | >= 0 < 4.6.2-1 | 4.6.2-1 |
| linux | linux_kernel | >= 0 < 4.6.2-1 | 4.6.2-1 |
| linux | linux_kernel | >= 0 < 4.6.2-1 | 4.6.2-1 |
| linux | linux_kernel | >= 0 < 4.6.2-1 | 4.6.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-129.178 | 3.13.0-129.178 |
| linux | linux_kernel | >= 0 < 4.4.0-93.116 | 4.4.0-93.116 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jg67-r7fp-4j3h: fs/ext4/inode
ghsa_unreviewed·2022-05-17
CVE-2017-7495 [MEDIUM] CWE-200 GHSA-jg67-r7fp-4j3h: fs/ext4/inode
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.
OSV
linux vulnerabilities
osv·2017-08-28·CVSS 5.5
CVE-2016-7914 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that an out of bounds read vulnerability existed in the
associative array implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash) or expose
sensitive information. (CVE-2016-7914)
It was discovered that a NULL pointer dereference existed in the Direct
Rendering Manager (DRM) driver for VMWare devices in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2017-7261)
It was discovered that the USB Cypress HID drivers for the Linux kernel did
not properly validate reported information from the device. An attacker
with physical access could use this to expose sensitive information (kernel
memory). (CVE-2017-7273)
A reference count bug was discovered
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-08-28·CVSS 5.5
CVE-2017-11176 [MEDIUM] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a use-after-free vulnerability existed in the POSIX
message queue implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-11176)
Huang Weller discovered that the ext4 filesystem implementation in the
Linux kernel mishandled a needs-flushing-before-commit list. A local
attacker could use this to expose sensitive information. (CVE-2017-7495)
It was discovered that a buffer overflow existed in the Broadcom FullMAC
WLAN driver in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2017-7541)
It was discovered t
OSV
linux-lts-xenial vulnerabilities
osv·2017-08-28·CVSS 5.5
CVE-2017-11176 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3405-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a use-after-free vulnerability existed in the POSIX
message queue implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-11176)
Huang Weller discovered that the ext4 filesystem implementation in the
Linux kernel mishandled a needs-flushing-before-commit list. A local
attacker could use this to expose sensitive information. (CVE-2017-7495)
It was discovered that a buffer overflow existed in the Broadcom FullMAC
WLAN drive
OSV
CVE-2017-7495: fs/ext4/inode
osv·2017-05-15·CVSS 5.5
CVE-2017-7495 [MEDIUM] CVE-2017-7495: fs/ext4/inode
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.
Android
CVE-2017-7495: File system
vendor_android·2017-09-01·CVSS 5.5
CVE-2017-7495 [MEDIUM] CVE-2017-7495: File system
Android Security Bulletin 2017-09-01
CVE: CVE-2017-7495
Severity: HIGH
Type: ID
Component: File system
References: A-62198330
Upstream kernel
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-08-29·CVSS 5.5
CVE-2016-7914 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3406-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that an out of bounds read vulnerability existed in the
associative array implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash) or expose
sensitive information. (CVE-2016-7914)
It was discovered that a NULL pointer dereference existed in the Direct
Rendering Manager (DRM) driver for VMWare devices in the Linux kernel. A
local attacker could use this to cause a denial of service (system cras
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-08-28·CVSS 5.5
CVE-2015-7837 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3405-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a use-after-free vulnerability existed in the POSIX
message queue implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-11176)
Huang Weller discovered that the ext4 filesystem implementation in the
Linux kernel mishandled a needs-flushing-before-commit list. A local
attacker could use this to expose sensitive information. (CVE-2017-7495)
I
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-28·CVSS 5.5
CVE-2015-7837 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a use-after-free vulnerability existed in the POSIX
message queue implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-11176)
Huang Weller discovered that the ext4 filesystem implementation in the
Linux kernel mishandled a needs-flushing-before-commit list. A local
attacker could use this to expose sensitive information. (CVE-2017-7495)
It was discovered that a buffer overflow existed in the Broadcom FullMAC
WLAN driver in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2017-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-28·CVSS 5.5
CVE-2016-7914 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that an out of bounds read vulnerability existed in the
associative array implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash) or expose
sensitive information. (CVE-2016-7914)
It was discovered that a NULL pointer dereference existed in the Direct
Rendering Manager (DRM) driver for VMWare devices in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2017-7261)
It was discovered that the USB Cypress HID drivers for the Linux kernel did
not properly validate reported information from the device. An attacker
with physical access could use this to expose sensitive in
Red Hat
kernel: ext4: power failure during write(2) causes on-disk information leak
vendor_redhat·2017-05-12·CVSS 5.5
CVE-2017-7495 [MEDIUM] CWE-665 kernel: ext4: power failure during write(2) causes on-disk information leak
kernel: ext4: power failure during write(2) causes on-disk information leak
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.
A vulnerability was found in the Linux kernel where filesystems mounted with data=ordered mode may allow an attacker to read stale data from recently allocated blocks in new files after a system 'reset' by abusing ext4 mechanics of delayed allocation.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6.
This
Debian
CVE-2017-7495: linux - fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is...
vendor_debian·2017·CVSS 5.5
CVE-2017-7495 [MEDIUM] CVE-2017-7495: linux - fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is...
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.
Scope: local
bookworm: resolved (fixed in 4.6.2-1)
bullseye: resolved (fixed in 4.6.2-1)
forky: resolved (fixed in 4.6.2-1)
sid: resolved (fixed in 4.6.2-1)
trixie: resolved (fixed in 4.6.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7495 kernel: ext4: power failure during write(2) causes on-disk information leak
bugzilla·2017-05-12·CVSS 5.5
CVE-2017-7495 [MEDIUM] CVE-2017-7495 kernel: ext4: power failure during write(2) causes on-disk information leak
CVE-2017-7495 kernel: ext4: power failure during write(2) causes on-disk information leak
A flaw was found in the kernels implementation of ext4 for filesystems mounted with data=ordered mode. Stale data from recently allocated blocks may appear in newly created blocks in files when a system is 'power reset'. This may allow an attacker to gain information about file contents being written to disk when the system was being reset. This issue only affects regular write()'s and not when an application is using direct IO.
In testing, the amount of stale-data leakage is at maximum the amount of outstanding delayed journal transactions to the underlying device since the last commit (defaulting to 5 seconds, but tunable/exasperated with commit=nrsec mount option).
Discussion:
Mitigation:
Alte
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=06bd3c36a733ac27962fea7d6f47168841376824http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.2http://www.openwall.com/lists/oss-security/2017/05/15/2http://www.securityfocus.com/bid/98491https://bugzilla.redhat.com/show_bug.cgi?id=1450261https://github.com/torvalds/linux/commit/06bd3c36a733ac27962fea7d6f47168841376824https://source.android.com/security/bulletin/2017-09-01http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=06bd3c36a733ac27962fea7d6f47168841376824http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.6.2http://www.openwall.com/lists/oss-security/2017/05/15/2http://www.securityfocus.com/bid/98491https://bugzilla.redhat.com/show_bug.cgi?id=1450261https://github.com/torvalds/linux/commit/06bd3c36a733ac27962fea7d6f47168841376824https://source.android.com/security/bulletin/2017-09-01
2017-05-15
Published