CVE-2018-1000004
published 2018-01-16CVE-2018-1000004: In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
3.54%
88.1th percentile
In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.14.17-1 (bookworm) | linux 4.14.17-1 (bookworm) |
| linux | linux_kernel | <= 2.6.0 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.14.17-1 | 4.14.17-1 |
| linux | linux_kernel | >= 0 < 4.14.17-1 | 4.14.17-1 |
| linux | linux_kernel | >= 0 < 4.14.17-1 | 4.14.17-1 |
| linux | linux_kernel | >= 0 < 4.14.17-1 | 4.14.17-1 |
| linux | linux_kernel | >= 0 < 3.13.0-161.211 | 3.13.0-161.211 |
| linux | linux_kernel | >= 0 < 4.4.0-121.145 | 4.4.0-121.145 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-23·CVSS 7.8
CVE-2015-8539 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Dmitry Vyukov discovered that the key management subsystem in the Linux
kernel did not properly restrict adding a key that already exists but is
negatively instantiated. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2015-8539)
It was discovered that a use-after-free vulnerability existed in the device
driver for XCeive xc2028/xc3028 tuners in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-7913)
Pengfei Ding (丁鹏飞), Chenfu Bao (包沉浮), and Lenx Wei (韦韬)
discovered a race condition in the generic SCSI driver (sg) of the Linux
kern
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-10-23·CVSS 7.8
CVE-2015-8539 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3798-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Dmitry Vyukov discovered that the key management subsystem in the Linux
kernel did not properly restrict adding a key that already exists but is
negatively instantiated. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2015-8539)
It was discovered that a use-after-free vulnerability existed in the device
driver for XCeive xc2028/xc3028 tuners in the Linux kernel. A local
attacker could use this to
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race condition existed in the
Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel when
handling ioctl()s. A local attacker could use this to cause a
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3631-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code.
Red Hat
kernel: Race condition in sound system can lead to denial of service
vendor_redhat·2018-01-10·CVSS 5.9
CVE-2018-1000004 [MEDIUM] CWE-362 kernel: Race condition in sound system can lead to denial of service
kernel: Race condition in sound system can lead to denial of service
In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition.
In the Linux kernel versions 4.12, 3.10, 2.6, and possibly earlier, a race condition vulnerability exists in the sound system allowing for a potential deadlock and memory corruption due to use-after-free condition and thus denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
Statement: This issue affects the version of Linux kernel package as shipped with Red Hat Enterprise Linux 5. This is not currently planned to be addressed in future updates of the prod
Debian
CVE-2018-1000004: linux - In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race conditi...
vendor_debian·2018·CVSS 5.9
CVE-2018-1000004 [MEDIUM] CVE-2018-1000004: linux - In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race conditi...
In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition.
Scope: local
bookworm: resolved (fixed in 4.14.17-1)
bullseye: resolved (fixed in 4.14.17-1)
forky: resolved (fixed in 4.14.17-1)
sid: resolved (fixed in 4.14.17-1)
trixie: resolved (fixed in 4.14.17-1)
GHSA
GHSA-x7p2-c23q-89vc: In the Linux kernel 4
ghsa_unreviewed·2022-05-13
CVE-2018-1000004 [HIGH] CWE-362 GHSA-x7p2-c23q-89vc: In the Linux kernel 4
In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition.
OSV
linux vulnerabilities
osv·2018-10-23·CVSS 7.8
CVE-2015-8539 [HIGH] linux vulnerabilities
linux vulnerabilities
Dmitry Vyukov discovered that the key management subsystem in the Linux
kernel did not properly restrict adding a key that already exists but is
negatively instantiated. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2015-8539)
It was discovered that a use-after-free vulnerability existed in the device
driver for XCeive xc2028/xc3028 tuners in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-7913)
Pengfei Ding (丁鹏飞), Chenfu Bao (包沉浮), and Lenx Wei (韦韬)
discovered a race condition in the generic SCSI driver (sg) of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash)
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race condition existed in the
Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel when
handling ioctl()s. A local attacker could use this to cause a denial of
service (system
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3631-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race conditi
Kernel
ALSA: seq: Don't allow resizing pool in use
kernel_security·2018-03-05·CVSS 5.9
CVE-2018-1000004 [MEDIUM] ALSA: seq: Don't allow resizing pool in use
ALSA: seq: Don't allow resizing pool in use
This is a fix for a (sort of) fallout in the recent commit
d15d662e89fc ("ALSA: seq: Fix racy pool initializations") for
CVE-2018-1000004.
As the pool resize deletes the existing cells, it may lead to a race
when another thread is writing concurrently, eventually resulting a
UAF.
A simple workaround is not to allow the pool resizing when the pool is
in use. It's an invalid behavior in anyway.
Fixes: d15d662e89fc ("ALSA: seq: Fix racy pool initializations")
Reported-by: 范龙飞
Reported-by: Nicolai Stange
Cc:
Signed-off-by: Takashi Iwai
Kernel
ALSA: seq: More protection for concurrent write and ioctl races
kernel_security·2018-03-05·CVSS 5.9
CVE-2018-1000004 [MEDIUM] ALSA: seq: More protection for concurrent write and ioctl races
ALSA: seq: More protection for concurrent write and ioctl races
This patch is an attempt for further hardening against races between
the concurrent write and ioctls. The previous fix d15d662e89fc
("ALSA: seq: Fix racy pool initializations") covered the race of the
pool initialization at writer and the pool resize ioctl by the
client->ioctl_mutex (CVE-2018-1000004). However, basically this mutex
should be applied more widely to the whole write operation for
avoiding the unexpected pool operations by another thread.
The only change outside snd_seq_write() is the additional mutex
argument to helper functions, so that we can unlock / relock the given
mutex temporarily during schedule() call for blocking write.
Fixes: d15d662e89fc ("ALSA: seq: Fix racy pool initializations")
Reported-by: 范龙飞
OSV
CVE-2018-1000004: In the Linux kernel 4
osv·2018-01-16·CVSS 5.9
CVE-2018-1000004 [MEDIUM] CVE-2018-1000004: In the Linux kernel 4
In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service [fedora-all]
bugzilla·2018-01-17·CVSS 5.9
CVE-2018-1000004 [MEDIUM] CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service [fedora-all]
CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service
bugzilla·2018-01-17·CVSS 5.9
CVE-2018-1000004 [MEDIUM] CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service
CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service
In the Linux kernel versions 4.12, 3.10, 2.6 and possibly earlier, a race condition vulnerability exists in the sound system allowing for a potential deadlock and memory corruption due to use-after-free condition and thus denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
http://seclists.org/oss-sec/2018/q1/51
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b3defb791b26ea0683a93a4f49c77ec45ec96f10
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1535316]
---
*** Bug 1534650 has been marked as a duplicate of this bug. ***
http://seclists.org/oss-sec/2018/q1/51http://www.securityfocus.com/bid/104606https://access.redhat.com/errata/RHSA-2018:0654https://access.redhat.com/errata/RHSA-2018:0676https://access.redhat.com/errata/RHSA-2018:1062https://access.redhat.com/errata/RHSA-2018:2390https://access.redhat.com/errata/RHSA-2019:1483https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlhttps://usn.ubuntu.com/3631-1/https://usn.ubuntu.com/3631-2/https://usn.ubuntu.com/3798-1/https://usn.ubuntu.com/3798-2/https://www.debian.org/security/2018/dsa-4187https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://seclists.org/oss-sec/2018/q1/51http://www.securityfocus.com/bid/104606https://access.redhat.com/errata/RHSA-2018:0654https://access.redhat.com/errata/RHSA-2018:0676https://access.redhat.com/errata/RHSA-2018:1062https://access.redhat.com/errata/RHSA-2018:2390https://access.redhat.com/errata/RHSA-2019:1483https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlhttps://usn.ubuntu.com/3631-1/https://usn.ubuntu.com/3631-2/https://usn.ubuntu.com/3798-1/https://usn.ubuntu.com/3798-2/https://www.debian.org/security/2018/dsa-4187https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2018-01-16
Published