CVE-2018-1000028
published 2018-02-09CVE-2018-1000028: Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd)…
PriorityP343high7.4CVSS 3.0
AVNACHPRNUINSUCHIHAN
EPSS
1.38%
69.4th percentile
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled. This vulnerability appears to have been fixed in after commit 1995266727fa.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.14.17-1 (bookworm) | linux 4.14.17-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.14.17-1 | 4.14.17-1 |
| linux | linux_kernel | >= 0 < 4.14.17-1 | 4.14.17-1 |
| linux | linux_kernel | >= 0 < 4.14.17-1 | 4.14.17-1 |
| linux | linux_kernel | >= 0 < 4.14.17-1 | 4.14.17-1 |
| linux | linux_kernel | 4.14.8 – 4.14.23 | — |
| linux | linux_kernel | 4.15.1 – 4.15.7 | — |
| linux | linux_kernel | 4.4.111 – 4.4.119 | — |
| linux | linux_kernel | 4.9.76 – 4.9.85 | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Improper sorting of GIDs in nfsd can lead to incorrect permissions being applied
vendor_redhat·2018-01-22·CVSS 7.4
CVE-2018-1000028 [HIGH] CWE-732 kernel: Improper sorting of GIDs in nfsd can lead to incorrect permissions being applied
kernel: Improper sorting of GIDs in nfsd can lead to incorrect permissions being applied
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled. This vulnerability appears to have been fixed in after commit 1995266727fa.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt
Debian
CVE-2018-1000028: linux - Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4....
vendor_debian·2018·CVSS 7.4
CVE-2018-1000028 [HIGH] CVE-2018-1000028: linux - Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4....
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled. This vulnerability appears to have been fixed in after commit 1995266727fa.
Scope: local
bookworm: resolved (fixed in 4.14.17-1)
bullseye: resolved (fixed in 4.14.17-1)
forky: resolved (fixed in 4.14.17-1)
sid: resolved (fixed in 4.14.17-1)
trixie: resolved (fixed in 4.14.17-1)
GHSA
GHSA-p7mv-684h-c4rx: Linux kernel version after commit bdcf0a423ea1 - 4
ghsa_unreviewed·2022-05-13
CVE-2018-1000028 [HIGH] CWE-269 GHSA-p7mv-684h-c4rx: Linux kernel version after commit bdcf0a423ea1 - 4
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled. This vulnerability appears to have been fixed in after commit 1995266727fa.
OSV
CVE-2018-1000028: Linux kernel version after commit bdcf0a423ea1 - 4
osv·2018-02-09·CVSS 7.4
CVE-2018-1000028 [HIGH] CVE-2018-1000028: Linux kernel version after commit bdcf0a423ea1 - 4
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled. This vulnerability appears to have been fixed in after commit 1995266727fa.
No detection rules found.
Bugzilla
CVE-2018-1000028 kernel: Improper sorting of GIDs in nfsd can lead to incorrect permissions being applied
bugzilla·2018-01-31·CVSS 7.4
CVE-2018-1000028 [HIGH] CVE-2018-1000028 kernel: Improper sorting of GIDs in nfsd can lead to incorrect permissions being applied
CVE-2018-1000028 kernel: Improper sorting of GIDs in nfsd can lead to incorrect permissions being applied
nfsd in the Linux kernel 4.15, does not properly sort gids when rootsquash is enabled. The groups_sort() function is called inside a loop that copies/squashes gids. he net result is that the highest numbered valid gids are replaced with any lower-valued garbage gids, possibly including 0.
This can corrupt group membership, leading to permission denials for the client.
Upstream Patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1995266727fa8143897e89b55f5d3c79aa828420
arXiv
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
arxiv_fulltext·2024-09-24
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
Bonan Ruan
National University of Singapore
Jiahao Liu
National University of Singapore
Chuqi Zhang
National University of Singapore
Zhenkai Liang
National University of Singapore
## Abstract
Linux kernel vulnerability reproduction is a critical task in system security.
To reproduce a kernel vulnerability, the vulnerable environment and the Proof of Concept (PoC) program are needed.
Most existing research focuses on the generation of PoC, while the construction of environment is overlooked.
However, establishing an effective vulnerable environment to trigger a vulnerability is challenging.
Firstly, it is hard to guarantee that the selected kernel version for reproduction is vulnerable, as the vulner
arXiv
Partially-Observable Security Games for Automating Attack-Defense Analysis
arxiv_fulltext·2022-11-02
Partially-Observable Security Games for Automating Attack-Defense Analysis
Partially-Observable Security Games for Automating Attack-Defense Analysis
Narges Khakpour
[email protected]
School of Computing, Newcastle University
Newcastle upon Tyne
UK
Department of Computer Science and Media Technology, Linnaeus University
Växjö
Sweden
David Parker
[email protected]
Department of Computer Science, Oxford University
Oxford
UK
## Abstract
Network systems often contain vulnerabilities that remain unfixed in a network for various reasons, such as the lack of a patch or knowledge to fix them. With the presence of such residual vulnerabilities, the network administrator should properly react to the malicious activities or proactively prevent them, by applying suitable countermeasures that minimize the likelihood of an attack by the attacker. In this
2018-02-09
Published