cbcvebase.
CVE-2018-12233
published 2018-06-12

CVE-2018-12233: In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two…

PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.34%
81.9th percentile
In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability can be triggered by an unprivileged user with the ability to create files and execute programs. A kmalloc call is incorrect, leading to slab-out-of-bounds in jfs_xattr.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.17.3-1 (bookworm)linux 4.17.3-1 (bookworm)
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 3.13.0-157.2073.13.0-157.207
linuxlinux_kernel>= 0 < 4.4.0-134.1604.4.0-134.160
linuxlinux_kernel>= 0 < 4.15.0-33.364.15.0-33.36
linuxlinux_kernel>= 2.6.12 < 3.16.583.16.58
linuxlinux_kernel>= 3.17 < 3.18.1183.18.118
linuxlinux_kernel>= 3.19 < 4.4.1474.4.147
linuxlinux_kernel>= 4.10 < 4.14.624.14.62
linuxlinux_kernel>= 4.15 < 4.17.144.17.14
linuxlinux_kernel>= 4.5 < 4.9.1194.9.119

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.