CVE-2018-1000199Improper Restriction of Operations within the Bounds of a Memory Buffer in Ubuntu Linux

Severity
5.5MEDIUMNVD
EPSS
0.5%
top 35.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 24
Latest updateMay 13

Description

The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Debianlinux/linux_kernel< 4.15.17-1+3
Ubuntulinux/linux_kernel< 3.13.0-147.196+1

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 17.10, Enterprise Linux 7.0, 7.2, 7.3, 7.4, 7.5

Patches

🔴Vulnerability Details

4
GHSA
GHSA-5qx2-85hg-v5cr: The Linux Kernel version 32022-05-13
CVEList
CVE-2018-1000199: The Linux Kernel version 32018-05-24
OSV
CVE-2018-1000199: The Linux Kernel version 32018-05-24
OSV
linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, linux-snapdragon vulnerabilities2018-05-08

📋Vendor Advisories

4
Ubuntu
Linux kernel vulnerabilities2018-05-08
Ubuntu
Linux kernel vulnerabilities2018-05-08
Red Hat
kernel: ptrace() incorrect error handling leads to corruption and DoS2018-05-01
Debian
CVE-2018-1000199: linux - The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modi...2018

💬Community

1
Bugzilla
CVE-2018-1000199 kernel: ptrace() incorrect error handling leads to corruption and DoS2018-04-17
CVE-2018-1000199 — Canonical Ubuntu Linux vulnerability | cvebase