CVE-2018-12633
published 2018-06-22CVE-2018-12633: An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice…
PriorityP426medium6.3CVSS 3.0
AVLACHPRLUINSUCHINAH
EPSS
0.26%
18.2th percentile
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.17.3-1 (bookworm) | linux 4.17.3-1 (bookworm) |
| linux | linux_kernel | <= 4.17.2 | — |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
| linux | linux_kernel | >= 0 < 4.17.3-1 | 4.17.3-1 |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:C
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service
vendor_redhat·2018-05-08·CVSS 6.3
CVE-2018-12633 [MEDIUM] CWE-362 kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service
kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not a
Debian
CVE-2018-12633: linux - An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioct...
vendor_debian·2018·CVSS 6.3
CVE-2018-12633 [MEDIUM] CVE-2018-12633: linux - An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioct...
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.
Scope: local
bookworm: resolved (fixed in 4.17.3-1)
bullseye: resolved (fixed in 4.17.3-1)
forky: resolved (fixed in 4.17.3-1)
sid: resolved (fixed in 4.17.3-1)
trixie: resolved (fixed in 4.17.3-1)
GHSA
GHSA-9rwp-mqvh-8g6q: An issue was discovered in the Linux kernel through 4
ghsa_unreviewed·2022-05-14
CVE-2018-12633 [MEDIUM] CWE-362 GHSA-9rwp-mqvh-8g6q: An issue was discovered in the Linux kernel through 4
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.
OSV
CVE-2018-12633: An issue was discovered in the Linux kernel through 4
osv·2018-06-22·CVSS 6.3
CVE-2018-12633 [MEDIUM] CVE-2018-12633: An issue was discovered in the Linux kernel through 4
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12633 kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service
bugzilla·2018-06-22·CVSS 6.3
CVE-2018-12633 [MEDIUM] CVE-2018-12633 kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service
CVE-2018-12633 kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.
References:
https://bugzilla.kernel.org/show_bug.cgi?id=200131
https://github.com/torvalds/linux/
Bugzilla
CVE-2018-12633 kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service [fedora-all]
bugzilla·2018-06-22·CVSS 6.3
CVE-2018-12633 [MEDIUM] CVE-2018-12633 kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service [fedora-all]
CVE-2018-12633 kernel: Double-fetch vulnerability in drivers/virt/vboxguest/vboxguest_linux.c:vbg_misc_device_ioctl() allows information leak and local denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed
Bugzilla
CVE-2017-12633 camel-hessian: Apache Camel's Hessian unmarshalling operation is vulnerable to Remote Code Execution attacks
bugzilla·2017-11-15·CVSS 9.8
CVE-2017-12633 [CRITICAL] CVE-2017-12633 camel-hessian: Apache Camel's Hessian unmarshalling operation is vulnerable to Remote Code Execution attacks
CVE-2017-12633 camel-hessian: Apache Camel's Hessian unmarshalling operation is vulnerable to Remote Code Execution attacks
Apache Camel's camel-hessian component is vulnerable to Java object
de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0
The unsupported Camel 2.x (2.18 and earlier) versions may be also affected.
References:
https://camel.apache.org/security-advisories.data/CVE-2017-12633.txt.asc
https://issues.apache.org/jira/browse/CAMEL-11923
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Fuse
Via RHSA-2018:0319 https://access.redhat.com/errata/RHSA-2018:0319
---
This vulnerability is out of security support scope for the following product:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=bd23a7269834dc7c1f93e83535d16ebc44b75ebahttps://bugzilla.kernel.org/show_bug.cgi?id=200131https://github.com/torvalds/linux/commit/bd23a7269834dc7c1f93e83535d16ebc44b75ebahttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=bd23a7269834dc7c1f93e83535d16ebc44b75ebahttps://bugzilla.kernel.org/show_bug.cgi?id=200131https://github.com/torvalds/linux/commit/bd23a7269834dc7c1f93e83535d16ebc44b75eba
2018-06-22
Published