CVE-2018-1095
published 2018-04-02CVE-2018-1095: The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.46%
70.9th percentile
The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.16.5-1 (bookworm) | linux 4.16.5-1 (bookworm) |
| linux | linux_kernel | <= 4.15.15 | — |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.15.0-24.26 | 4.15.0-24.26 |
| linux | linux_kernel | >= 0 < 4.15.0-29.31 | 4.15.0-29.31 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m6f7-q6m8-788v: The ext4_xattr_check_entries function in fs/ext4/xattr
ghsa_unreviewed·2022-05-14
CVE-2018-1095 [HIGH] CWE-476 GHSA-m6f7-q6m8-788v: The ext4_xattr_check_entries function in fs/ext4/xattr
The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.
OSV
linux-hwe, linux-azure, linux-gcp regression
osv·2018-07-21·CVSS 5.5
CVE-2018-1108 [MEDIUM] linux-hwe, linux-azure, linux-gcp regression
linux-hwe, linux-azure, linux-gcp regression
USN-3695-2 fixed vulnerabilities in the Linux Hardware Enablement
Kernel (HWE) kernel for Ubuntu 16.04 LTS. Unfortunately, the fix
for CVE-2018-1108 introduced a regression where insufficient early
entropy prevented services from starting, leading in some situations
to a failure to boot, This update addresses the issue.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that the Linux kernel's implementation of random
seed data reported that it was in a ready state before it had gathered
sufficient entropy. An attacker could use this to expose sensitive
information. (CVE-2018-1108)
Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly initialize the crc32c checksum d
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem regression
osv·2018-07-21·CVSS 5.5
CVE-2018-1108 [MEDIUM] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem regression
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem regression
USN-3695-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. Unfortunately, the fix for CVE-2018-1108 introduced a regression
where insufficient early entropy prevented services from starting,
leading in some situations to a failure to boot, This update addresses
the issue.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that the Linux kernel's implementation of random
seed data reported that it was in a ready state before it had gathered
sufficient entropy. An attacker could use this to expose sensitive
information. (CVE-2018-1108)
Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly initialize the crc32c checksum drive
OSV
linux-hwe, linux-azure vulnerabilities
osv·2018-07-02·CVSS 5.5
CVE-2018-1094 [MEDIUM] linux-hwe, linux-azure vulnerabilities
linux-hwe, linux-azure vulnerabilities
USN-3695-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly initialize the crc32c checksum driver. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2018-1094)
It was discovered that the cdrom driver in the Linux kernel contained an
incorrect bounds check. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-10940)
Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly validate xattr sizes. A l
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2018-07-02·CVSS 5.5
CVE-2018-1094 [MEDIUM] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
Wen Xu discovered that the ext4 filesystem implementation in the Linux
kernel did not properly initialize the crc32c checksum driver. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2018-1094)
It was discovered that the cdrom driver in the Linux kernel contained an
incorrect bounds check. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-10940)
Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly validate xattr sizes. A local attacker could use
this to cause a denial of service (system crash). (CVE-2018-1095)
Jann Horn discovered that the 32 bit adjtimex() syscall implementation
OSV
CVE-2018-1095: The ext4_xattr_check_entries function in fs/ext4/xattr
osv·2018-04-02·CVSS 5.5
CVE-2018-1095 [MEDIUM] CVE-2018-1095: The ext4_xattr_check_entries function in fs/ext4/xattr
The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.
Kernel
ext4: limit xattr size to INT_MAX
kernel_security·2018-03-29·CVSS 5.5
CVE-2018-1095 [MEDIUM] ext4: limit xattr size to INT_MAX
ext4: limit xattr size to INT_MAX
ext4 isn't validating the sizes of xattrs where the value of the xattr
is stored in an external inode. This is problematic because
->e_value_size is a u32, but ext4_xattr_get() returns an int. A very
large size is misinterpreted as an error code, which ext4_get_acl()
translates into a bogus ERR_PTR() for which IS_ERR() returns false,
causing a crash.
Fix this by validating that all xattrs are
Signed-off-by: Eric Biggers
Signed-off-by: Theodore Ts'o
Cc: [email protected]
Fixes: e50e5129f384 ("ext4: xattr-in-inode support")
Ubuntu
Linux kernel regression
vendor_ubuntu·2018-07-21·CVSS 5.5
CVE-2018-1108 [MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: A regression that caused boot failures was fixed in the Linux kernel.
USN-3695-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. Unfortunately, the fix for CVE-2018-1108 introduced a regression
where insufficient early entropy prevented services from starting,
leading in some situations to a failure to boot, This update addresses
the issue.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that the Linux kernel's implementation of random
seed data reported that it was in a ready state before it had gathered
sufficient entropy. An attacker could use this to expose sensitive
information. (CVE-2018-1108)
Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly
Ubuntu
Linux kernel (HWE) regression
vendor_ubuntu·2018-07-21·CVSS 5.5
CVE-2018-1108 [MEDIUM] Linux kernel (HWE) regression
Title: Linux kernel (HWE) regression
Summary: A regression that caused boot failures was fixed in the Linux kernel.
USN-3695-2 fixed vulnerabilities in the Linux Hardware Enablement
Kernel (HWE) kernel for Ubuntu 16.04 LTS. Unfortunately, the fix
for CVE-2018-1108 introduced a regression where insufficient early
entropy prevented services from starting, leading in some situations
to a failure to boot, This update addresses the issue.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that the Linux kernel's implementation of random
seed data reported that it was in a ready state before it had gathered
sufficient entropy. An attacker could use this to expose sensitive
information. (CVE-2018-1108)
Wen Xu discovered that the ext4 file system implementati
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-07-02·CVSS 5.5
CVE-2018-1094 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3695-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly initialize the crc32c checksum driver. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2018-1094)
It was discovered that the cdrom driver in the Linux kernel contained an
incorrect bounds check. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-10940)
Wen Xu discovered that the ext4 file system implemen
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-07-02·CVSS 5.5
CVE-2018-1094 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Xu discovered that the ext4 filesystem implementation in the Linux
kernel did not properly initialize the crc32c checksum driver. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2018-1094)
It was discovered that the cdrom driver in the Linux kernel contained an
incorrect bounds check. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-10940)
Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly validate xattr sizes. A local attacker could use
this to cause a denial of service (system crash). (CVE-2018-1095)
Jann Horn discovered that the 32 bit adjtimex() syscall imple
Red Hat
kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image
vendor_redhat·2018-03-22·CVSS 5.5
CVE-2018-1095 [MEDIUM] CWE-476 kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image
kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image
The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.
The Linux kernel is vulnerable to an out-of-bound access bug in the fs/posix_acl.c:get_acl() function. An attacker could trick a legitimate user or a privileged attacker could exploit this to cause a system crash or other unspecified impact with a crafted ext4 image. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is
Debian
CVE-2018-1095: linux - The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel thr...
vendor_debian·2018·CVSS 5.5
CVE-2018-1095 [MEDIUM] CVE-2018-1095: linux - The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel thr...
The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.
Scope: local
bookworm: resolved (fixed in 4.16.5-1)
bullseye: resolved (fixed in 4.16.5-1)
forky: resolved (fixed in 4.16.5-1)
sid: resolved (fixed in 4.16.5-1)
trixie: resolved (fixed in 4.16.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
bugzilla·2018-04-26·CVSS 6.5
CVE-2018-10177 [MEDIUM] CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
ImageMagick through version 7.0.7-28 is vulnerable to an infinite loop in coders/png.c:ReadOneMNGImage(). An attacker could exploit this to cause a denial of service via crafted MNG file.
References:
https://github.com/ImageMagick/ImageMagick/issues/1095
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1572045]
---
Upstream commit:
https://github.com/ImageMagick/ImageMagick6/commit/9eda4b36a8695e4a0cd27bea28b9c173c68a01ec
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now clo
Bugzilla
CVE-2018-1095 kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image [fedora-all]
bugzilla·2018-03-27·CVSS 5.5
CVE-2018-1095 [MEDIUM] CVE-2018-1095 kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image [fedora-all]
CVE-2018-1095 kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2018-1095 kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image
bugzilla·2018-03-27·CVSS 5.5
CVE-2018-1095 [MEDIUM] CVE-2018-1095 kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image
CVE-2018-1095 kernel: out-of-bound access in fs/posix_acl.c:get_acl() causes crash with crafted ext4 image
The Linux kernel is vulnerable to an out-of-bound access bug in the fs/posix_acl.c:get_acl() function. An attacker could trick a legitimate user or a privileged attacker could exploit this to cause a system crash or other unspecified impact with a crafted ext4 image. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://bugzilla.kernel.org/show_bug.cgi?id=199185
http://seclists.org/oss-sec/2018/q1/284
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=54dd0e0a1b255
Discussion:
Acknowledgments:
Name: Wen Xu
---
Created kernel tracking bugs for this i
http://openwall.com/lists/oss-security/2018/03/29/1https://access.redhat.com/errata/RHSA-2018:2948https://bugzilla.kernel.org/show_bug.cgi?id=199185https://bugzilla.redhat.com/show_bug.cgi?id=1560793https://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4.git/commit/?id=ce3fd194fcc6fbdc00ce095a852f22df97baa401https://usn.ubuntu.com/3695-1/https://usn.ubuntu.com/3695-2/http://openwall.com/lists/oss-security/2018/03/29/1https://access.redhat.com/errata/RHSA-2018:2948https://bugzilla.kernel.org/show_bug.cgi?id=199185https://bugzilla.redhat.com/show_bug.cgi?id=1560793https://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4.git/commit/?id=ce3fd194fcc6fbdc00ce095a852f22df97baa401https://usn.ubuntu.com/3695-1/https://usn.ubuntu.com/3695-2/
2018-04-02
Published