CVE-2018-10902Use After Free in Linux

Severity
7.8HIGHNVD
OSV5.5
EPSS
0.0%
top 88.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21
Latest updateMay 13

Description

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

Debianlinux/linux_kernel< 4.17.15-1+3
Ubuntulinux/linux_kernel< 3.13.0-164.214+2
debiandebian/linux< linux 4.17.15-1 (bookworm)

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 18.04

Patches

🔴Vulnerability Details

8
GHSA
GHSA-fw8c-q6fq-37rg: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_i2022-05-13
OSV
linux vulnerabilities2018-12-20
OSV
linux-azure vulnerabilities2018-12-20
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities2018-12-20
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities2018-12-20

📋Vendor Advisories

9
Ubuntu
Linux kernel (HWE) vulnerabilities2018-12-20
Ubuntu
Linux kernel vulnerabilities2018-12-20
Ubuntu
Linux kernel vulnerabilities2018-12-20
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2018-12-20
Ubuntu
Linux kernel (Azure) vulnerabilities2018-12-20

💬Community

2
Bugzilla
CVE-2018-10902 kernel: MIDI driver race condition leads to a double-free [fedora-all]2018-08-22
Bugzilla
CVE-2018-10902 kernel: MIDI driver race condition leads to a double-free2018-06-13
CVE-2018-10902 — Use After Free in Debian Linux | cvebase