cbcvebase.
CVE-2018-12633
published 2018-06-22

CVE-2018-12633: An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice…

PriorityP426medium6.3CVSS 3.0
AVLACHPRLUINSUCHINAH
EPSS
0.26%
18.2th percentile
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.17.3-1 (bookworm)linux 4.17.3-1 (bookworm)
linuxlinux_kernel<= 4.17.2
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1
linuxlinux_kernel>= 0 < 4.17.3-14.17.3-1

CVSS provenance

nvdv3.06.3MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:C
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.