CVE-2018-10882
published 2018-07-27CVE-2018-10882: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and…
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.72%
49.9th percentile
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.17.3-1 (bookworm) | linux 4.17.3-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.4.0-134.160 | 4.4.0-134.160 |
| linux | linux_kernel | >= 0 < 4.15.0-44.47 | 4.15.0-44.47 |
| linux | linux_kernel | >= 0 < 4.15.0-45.48 | 4.15.0-45.48 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2019-02-07·CVSS 5.0
CVE-2018-10876 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
e
Ubuntu
Linux kernel (AWS, GCP, KVM, OEM, Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2019-02-04·CVSS 5.0
CVE-2018-10876 [MEDIUM] Linux kernel (AWS, GCP, KVM, OEM, Raspberry Pi 2) vulnerabilities
Title: Linux kernel (AWS, GCP, KVM, OEM, Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write v
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-02-04·CVSS 5.0
CVE-2018-10876 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malici
Ubuntu
Linux kernel regression
vendor_ubuntu·2019-01-31·CVSS 5.0
[MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: Multiple regressions were fixed in the Linux kernel.
USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. Unfortunately, that update introduced regressions with docking
station displays and mounting ext4 file systems with the meta_bg
option enabled. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesy
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-01-29·CVSS 5.0
CVE-2018-10876 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
ext4 file
Android
CVE-2018-10882: ext4 filesystem
vendor_android·2019-01-01·CVSS 4.8
CVE-2018-10882 [MEDIUM] CVE-2018-10882: ext4 filesystem
Android Security Bulletin 2019-01-01
CVE: CVE-2018-10882
Severity: HIGH
Type: EoP
Component: ext4 filesystem
References: A-116406626
Upstream
kernel
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-08-24·CVSS 7.8
CVE-2017-13168 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3753-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-08-24·CVSS 7.8
CVE-2017-13168 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use thi
Red Hat
kernel: stack-out-of-bounds write infs/jbd2/transaction.c
vendor_redhat·2018-06-14·CVSS 4.8
CVE-2018-10882 [MEDIUM] CWE-787 kernel: stack-out-of-bounds write infs/jbd2/transaction.c
kernel: stack-out-of-bounds write infs/jbd2/transaction.c
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in the fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) -
Debian
CVE-2018-10882: linux - A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a...
vendor_debian·2018·CVSS 4.8
CVE-2018-10882 [MEDIUM] CVE-2018-10882: linux - A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a...
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
Scope: local
bookworm: resolved (fixed in 4.17.3-1)
bullseye: resolved (fixed in 4.17.3-1)
forky: resolved (fixed in 4.17.3-1)
sid: resolved (fixed in 4.17.3-1)
trixie: resolved (fixed in 4.17.3-1)
GHSA
GHSA-pvv9-p2gj-w426: A flaw was found in the Linux kernel's ext4 filesystem
ghsa_unreviewed·2022-05-13
CVE-2018-10882 [MEDIUM] CWE-787 GHSA-pvv9-p2gj-w426: A flaw was found in the Linux kernel's ext4 filesystem
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
OSV
linux-azure vulnerabilities
osv·2019-02-07·CVSS 5.5
CVE-2018-10876 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
ext4 filesystem implementation in the Linux kernel. An attacker could use
this to c
OSV
linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2019-02-04·CVSS 5.5
CVE-2018-10876 [MEDIUM] linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
ext4 filesystem implementation in the
OSV
linux-hwe, linux-aws-hwe, linux-gcp vulnerabilities
osv·2019-02-04·CVSS 5.5
[MEDIUM] linux-hwe, linux-aws-hwe, linux-gcp vulnerabilities
linux-hwe, linux-aws-hwe, linux-gcp vulnerabilities
USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial
OSV
linux regression
osv·2019-01-31·CVSS 5.5
[MEDIUM] linux regression
linux regression
USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. Unfortunately, that update introduced regressions with docking
station displays and mounting ext4 file systems with the meta_bg
option enabled. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to constr
OSV
linux vulnerabilities
osv·2019-01-29·CVSS 5.5
CVE-2018-10876 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
ext4 filesystem implementation in the Linux kernel. An attacker could use
this to constru
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-08-24·CVSS 7.8
CVE-2017-13168 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-08-24·CVSS 7.8
CVE-2017-13168 [HIGH] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3753-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-1
OSV
CVE-2018-10882: A flaw was found in the Linux kernel's ext4 filesystem
osv·2018-07-27·CVSS 5.5
CVE-2018-10882 [MEDIUM] CVE-2018-10882: A flaw was found in the Linux kernel's ext4 filesystem
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
Kernel
ext4: add more inode number paranoia checks
kernel_security·2018-06-17·CVSS 4.8
CVE-2018-10882 [MEDIUM] ext4: add more inode number paranoia checks
ext4: add more inode number paranoia checks
If there is a directory entry pointing to a system inode (such as a
journal inode), complain and declare the file system to be corrupted.
Also, if the superblock's first inode number field is too small,
refuse to mount the file system.
This addresses CVE-2018-10882.
https://bugzilla.kernel.org/show_bug.cgi?id=200069
Signed-off-by: Theodore Ts'o
Cc: [email protected]
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10882 kernel: stack-out-of-bounds write infs/jbd2/transaction.c
bugzilla·2018-06-29·CVSS 4.8
CVE-2018-10882 [MEDIUM] CVE-2018-10882 kernel: stack-out-of-bounds write infs/jbd2/transaction.c
CVE-2018-10882 kernel: stack-out-of-bounds write infs/jbd2/transaction.c
A flaw was found in the Linux kernel's ext4 file system. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, which can lead to memory corruption. This can mean that the memory can be corrupted to create a denial of service, and a system crash or privilege escalation by unmounting a crafted ext4 filesystem image.
References:
https://bugzilla.kernel.org/show_bug.cgi?id=200069
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c37e9e013469521d9adb932d17a1795c139b36db
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1596843]
---
This is fixed for Fedora with the 4.17.6 stable kernel update
---
Notes:
Whil
Bugzilla
CVE-2018-10882 kernel: stack-out-of-bounds write infs/jbd2/transaction.c [fedora-all]
bugzilla·2018-06-29·CVSS 4.8
CVE-2018-10882 [MEDIUM] CVE-2018-10882 kernel: stack-out-of-bounds write infs/jbd2/transaction.c [fedora-all]
CVE-2018-10882 kernel: stack-out-of-bounds write infs/jbd2/transaction.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
arXiv
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
arxiv_fulltext·2019-05-22
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
1.55cm
[1]
\@fnsymbol#1
Hey Google, What Exactly Do Your Security Patches Tell Us?\ Large-Scale Empirical Study on Android Patched Vulnerabilities
Sadegh Farhang Sadegh Farhang and Mehmet Bahadir Kirdan equally contributed to this work.
Pennsylvania State University
[email protected]
Mehmet Bahadir Kirdan 1
Technical University of Munich
[email protected]
Aron Laszka
University of Houston
[email protected]
Jens Grossklags
Technical University of Munich
[email protected]
## Abstract
Android has the largest market share among smartphone platforms worldwide with more than one billion active devices.
Like other platforms, security patches play a pivotal role in keeping Android devices safe from the exploitation of known vulnerabilities. Previous research efforts have documente
http://www.securityfocus.com/bid/106503https://access.redhat.com/errata/RHSA-2018:2948https://bugzilla.kernel.org/show_bug.cgi?id=200069https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10882https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c37e9e013469521d9adb932d17a1795c139b36dbhttps://lists.debian.org/debian-lts-announce/2018/07/msg00020.htmlhttps://usn.ubuntu.com/3753-1/https://usn.ubuntu.com/3753-2/https://usn.ubuntu.com/3871-1/https://usn.ubuntu.com/3871-3/https://usn.ubuntu.com/3871-4/https://usn.ubuntu.com/3871-5/http://www.securityfocus.com/bid/106503https://access.redhat.com/errata/RHSA-2018:2948https://bugzilla.kernel.org/show_bug.cgi?id=200069https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10882https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c37e9e013469521d9adb932d17a1795c139b36dbhttps://lists.debian.org/debian-lts-announce/2018/07/msg00020.htmlhttps://usn.ubuntu.com/3753-1/https://usn.ubuntu.com/3753-2/https://usn.ubuntu.com/3871-1/https://usn.ubuntu.com/3871-3/https://usn.ubuntu.com/3871-4/https://usn.ubuntu.com/3871-5/
2018-07-27
Published