cbcvebase.
CVE-2018-1000204
published 2018-06-26

CVE-2018-1000204: Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead…

PriorityP431medium5.3CVSS 3.0
AVNACHPRLUINSUCHINAN
EPSS
1.91%
77.8th percentile
Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://github.com/torvalds/linux/commit/a45b599ad808c3c982fdcdc12b0b8611c2f92824 already. The problem has limited scope, as users don't usually have permissions to access SCSI devices. On the other hand, e.g. the Nero user manual suggests doing `chmod o+r+w /dev/sg*` to make the devices accessible. NOTE: third parties dispute the relevance of this report, noting that the requirement for an attacker to have both the CAP_SYS_ADMIN and CAP_SYS_RAWIO capabilities makes it "virtually impossible to exploit.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.16.18-1 (bookworm)linux 5.16.18-1 (bookworm)
debianlinux< linux 4.16.12-1 (bookworm)linux 4.16.12-1 (bookworm)
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fd97de9c7b973f46a6103f4170c5efc7b8ef8797fd97de9c7b973f46a6103f4170c5efc7b8ef8797
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < aaf166f37eb6bb55d81c3e40a2a460c8875c8813aaf166f37eb6bb55d81c3e40a2a460c8875c8813
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 06cb238b0f7ac1669cb06390704c61794724c19106cb238b0f7ac1669cb06390704c61794724c191
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b2f140a9f980806f572d672e1780acea66b9a25cb2f140a9f980806f572d672e1780acea66b9a25c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f3f2247ac31cb71d1f05f56536df5946c6652f4af3f2247ac31cb71d1f05f56536df5946c6652f4a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7007c894631cf43041dcfa0da7142bbaa7eb673c7007c894631cf43041dcfa0da7142bbaa7eb673c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dcead36b19d999d687cd9c99b7f37520d9102b57dcead36b19d999d687cd9c99b7f37520d9102b57
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f2141881b530738777c28bb51c62175895c8178bf2141881b530738777c28bb51c62175895c8178b
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 901c7280ca0d5e2b4a8929fbe0bfb007ac2a6544901c7280ca0d5e2b4a8929fbe0bfb007ac2a6544

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.06.3MEDIUMAV:N/AC:M/Au:S/C:C/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.