CVE-2018-1000199
published 2018-05-24CVE-2018-1000199: The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory…
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
1.22%
65.3th percentile
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.15.17-1 (bookworm) | linux 4.15.17-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.15.17-1 | 4.15.17-1 |
| linux | linux_kernel | >= 0 < 4.15.17-1 | 4.15.17-1 |
| linux | linux_kernel | >= 0 < 4.15.17-1 | 4.15.17-1 |
| linux | linux_kernel | >= 0 < 4.15.17-1 | 4.15.17-1 |
| linux | linux_kernel | >= 0 < 3.13.0-147.196 | 3.13.0-147.196 |
| linux | linux_kernel | >= 0 < 4.4.0-124.148 | 4.4.0-124.148 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-05-08·CVSS 5.5
CVE-2018-1000199 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3641-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS, Ubuntu 16.04 LTS, and Ubuntu 17.10. This update provides the
corresponding updates for Ubuntu 12.04 ESM.
Nick Peterson discovered that the Linux kernel did not properly handle
debug exceptions following a MOV/POP to SS instruction. A local attacker
could use this to cause a denial of service (system crash). This issue only
affected the amd64 architecture. (CVE-2018-8897)
Andy Lutomirski discovered that the KVM subsystem of the Linux kernel did
not properly emulate the ICEBP instruction following a MOV/POP to SS
instruction. A local attacker in a KVM virtual machine could use this to
cause a denial of service (gue
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-05-08·CVSS 5.5
CVE-2018-1000199 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Nick Peterson discovered that the Linux kernel did not
properly handle debug exceptions following a MOV/POP to SS
instruction. A local attacker could use this to cause a denial
of service (system crash). This issue only affected the amd64
architecture. (CVE-2018-8897)
Andy Lutomirski discovered that the KVM subsystem of the Linux kernel
did not properly emulate the ICEBP instruction following a MOV/POP
to SS instruction. A local attacker in a KVM virtual machine could
use this to cause a denial of service (guest VM crash) or possibly
escalate privileges inside of the virtual machine. This issue only
affected the i386 and amd64 architectures. (CVE-2018-1087)
Andy Lutomirski discovered th
Red Hat
kernel: ptrace() incorrect error handling leads to corruption and DoS
vendor_redhat·2018-05-01·CVSS 5.5
CVE-2018-1000199 [MEDIUM] CWE-460 kernel: ptrace() incorrect error handling leads to corruption and DoS
kernel: ptrace() incorrect error handling leads to corruption and DoS
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.
An address corruption flaw was discovered in the Linux kernel built with hardware breakpoint (CONFIG_HAVE_HW_BREAKPOINT) support. While modifying a h/w breakpoint via 'modify_user_hw_breakpoint' routine, an unprivileged user/process could use this flaw to crash the system kernel resulting in DoS OR to potentially escalate privileges on a the system.
Statement: This iss
Debian
CVE-2018-1000199: linux - The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modi...
vendor_debian·2018·CVSS 5.5
CVE-2018-1000199 [MEDIUM] CVE-2018-1000199: linux - The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modi...
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.
Scope: local
bookworm: resolved (fixed in 4.15.17-1)
bullseye: resolved (fixed in 4.15.17-1)
forky: resolved (fixed in 4.15.17-1)
sid: resolved (fixed in 4.15.17-1)
trixie: resolved (fixed in 4.15.17-1)
GHSA
GHSA-5qx2-85hg-v5cr: The Linux Kernel version 3
ghsa_unreviewed·2022-05-13
CVE-2018-1000199 [MEDIUM] CWE-119 GHSA-5qx2-85hg-v5cr: The Linux Kernel version 3
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.
OSV
CVE-2018-1000199: The Linux Kernel version 3
osv·2018-05-24·CVSS 5.5
CVE-2018-1000199 [MEDIUM] CVE-2018-1000199: The Linux Kernel version 3
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.
OSV
linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-05-08·CVSS 5.5
CVE-2018-8897 [MEDIUM] linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, linux-snapdragon vulnerabilities
Nick Peterson discovered that the Linux kernel did not
properly handle debug exceptions following a MOV/POP to SS
instruction. A local attacker could use this to cause a denial
of service (system crash). This issue only affected the amd64
architecture. (CVE-2018-8897)
Andy Lutomirski discovered that the KVM subsystem of the Linux kernel
did not properly emulate the ICEBP instruction following a MOV/POP
to SS instruction. A local attacker in a KVM virtual machine could
use this to cause a denial of service (guest VM crash) or possibly
escalate privileges inside of the virtual machine. This issue only
affected the i386 and amd64 architect
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlhttp://www.securitytracker.com/id/1040806https://access.redhat.com/errata/RHSA-2018:1318https://access.redhat.com/errata/RHSA-2018:1345https://access.redhat.com/errata/RHSA-2018:1347https://access.redhat.com/errata/RHSA-2018:1348https://access.redhat.com/errata/RHSA-2018:1354https://access.redhat.com/errata/RHSA-2018:1355https://access.redhat.com/errata/RHSA-2018:1374https://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlhttps://lkml.org/lkml/2018/4/6/813https://usn.ubuntu.com/3641-1/https://usn.ubuntu.com/3641-2/https://www.debian.org/security/2018/dsa-4187https://www.debian.org/security/2018/dsa-4188http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlhttp://www.securitytracker.com/id/1040806https://access.redhat.com/errata/RHSA-2018:1318https://access.redhat.com/errata/RHSA-2018:1345https://access.redhat.com/errata/RHSA-2018:1347https://access.redhat.com/errata/RHSA-2018:1348https://access.redhat.com/errata/RHSA-2018:1354https://access.redhat.com/errata/RHSA-2018:1355https://access.redhat.com/errata/RHSA-2018:1374https://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlhttps://lkml.org/lkml/2018/4/6/813https://usn.ubuntu.com/3641-1/https://usn.ubuntu.com/3641-2/https://www.debian.org/security/2018/dsa-4187https://www.debian.org/security/2018/dsa-4188
2018-05-24
Published