CVE-2018-12896
published 2018-07-02CVE-2018-12896: An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the…
PriorityP419medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.64%
47.1th percentile
An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random. For example, a local user can cause a denial of service (signed integer overflow) via crafted mmap, futex, timer_create, and timer_settime system calls.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.18.20-1 (bookworm) | linux 4.18.20-1 (bookworm) |
| linux | linux_kernel | <= 4.17.3 | — |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 3.13.0-164.214 | 3.13.0-164.214 |
| linux | linux_kernel | >= 0 < 4.4.0-141.167 | 4.4.0-141.167 |
| linux | linux_kernel | >= 0 < 4.15.0-43.46 | 4.15.0-43.46 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-752f-2m5c-7473: An issue was discovered in the Linux kernel through 4
ghsa_unreviewed·2022-05-14
CVE-2018-12896 [MEDIUM] CWE-190 GHSA-752f-2m5c-7473: An issue was discovered in the Linux kernel through 4
An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random. For example, a local user can cause a denial of service (signed integer overflow) via crafted mmap, futex, timer_create, and timer_settime system calls.
OSV
linux vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux ke
OSV
linux-azure vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] linux-azure vulnerabilities
linux-azure vulnerabilities
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-12-20·CVSS 9.8
CVE-2017-18174 [CRITICAL] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3848-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a double free existed in the AMD GPIO driver in the
Linux kernel. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2017-18174)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Kanda Motohiro discovered that writing extended attributes to an XFS file
system in the Linux kernel in certain situations
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
osv·2018-12-20·CVSS 7.8
[HIGH] linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerabili
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that the YURE
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-12-20·CVSS 9.8
CVE-2017-18174 [CRITICAL] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a double free existed in the AMD GPIO driver in the
Linux kernel. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2017-18174)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Kanda Motohiro discovered that writing extended attributes to an XFS file
system in the Linux kernel in certain situations could cause an error
condition to occur. A local attacker could use this to cause a denial of
service. (CVE-2018-18690)
It was discovered that an integer overflow vulnerability exi
OSV
CVE-2018-12896: An issue was discovered in the Linux kernel through 4
osv·2018-07-02·CVSS 5.5
CVE-2018-12896 [MEDIUM] CVE-2018-12896: An issue was discovered in the Linux kernel through 4
An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random. For example, a local user can cause a denial of service (signed integer overflow) via crafted mmap, futex, timer_create, and timer_settime system calls.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus d
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 9.8
CVE-2017-18174 [CRITICAL] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a double free existed in the AMD GPIO driver in the
Linux kernel. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2017-18174)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Kanda Motohiro discovered that writing extended attributes to an XFS file
system in the Linux kernel in certain situations could cause an error
condition to occur. A local attacker could use this to cause a denial of
service. (CVE-2018-18690)
It was discovered that an integer
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 9.8
CVE-2017-18174 [CRITICAL] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3848-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a double free existed in the AMD GPIO driver in the
Linux kernel. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2017-18174)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Kanda Motohiro discovered that writing extended att
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-a
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3849-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was di
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered th
Red Hat
kernel: Integer overflow in kernel/time/posix-timers.c
vendor_redhat·2018-06-22·CVSS 5.5
CVE-2018-12896 [MEDIUM] CWE-190 kernel: Integer overflow in kernel/time/posix-timers.c
kernel: Integer overflow in kernel/time/posix-timers.c
An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random. For example, a local user can cause a denial of service (signed integer overflow) via crafted mmap, futex, timer_create, and timer_settime system calls.
An issue was discovered in the Linux kernel where an integer overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the over
Debian
CVE-2018-12896: linux - An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow ...
vendor_debian·2018·CVSS 5.5
CVE-2018-12896 [MEDIUM] CVE-2018-12896: linux - An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow ...
An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random. For example, a local user can cause a denial of service (signed integer overflow) via crafted mmap, futex, timer_create, and timer_settime system calls.
Scope: local
bookworm: resolved (fixed in 4.18.20-1)
bullseye: resolved (fixed in 4.18.20-1)
forky: resolved (fixed in 4.18.20-1)
sid: resolved (fixed in 4.18.20-1)
trixie: resolved (fixed in 4.18.20-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12896 kernel: Integer overflow in kernel/time/posix-timers.c
bugzilla·2018-07-03·CVSS 5.5
CVE-2018-12896 [MEDIUM] CVE-2018-12896 kernel: Integer overflow in kernel/time/posix-timers.c
CVE-2018-12896 kernel: Integer overflow in kernel/time/posix-timers.c
An issue was discovered in the Linux kernel. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random.
References:
https://bugzilla.kernel.org/show_bug.cgi?id=200189
https://github.com/lcytxw/bug_repro/tree/master/bug_200189
https://marc.info/?t=153003602900042&r=1&w=2
https://marc.info/?t=153003602700045&r=1&w=2
A suggested upstream patch:
https://github.com/torvalds/linux/commit/78c9c4dfbf8c0488394
Bugzilla
CVE-2018-12896 kernel: Integer overflow in kernel/time/posix-timers.c [fedora-all]
bugzilla·2018-07-03·CVSS 5.5
CVE-2018-12896 [MEDIUM] CVE-2018-12896 kernel: Integer overflow in kernel/time/posix-timers.c [fedora-all]
CVE-2018-12896 kernel: Integer overflow in kernel/time/posix-timers.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
arXiv
LineVD: Statement-level Vulnerability Detection using Graph Neural Networks
arxiv_fulltext·2022-03-25
LineVD: Statement-level Vulnerability Detection using Graph Neural Networks
: Statement-level Vulnerability Detection using Graph Neural Networks
David Hin
CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide
Cyber Security Cooperative Research Centre
Adelaide
Australia, 5005
[email protected]
Andrey Kan
AWS AI Labs**This work was done prior to joining Amazon
Adelaide
SA
Australia, 5005
[email protected]
Huaming Chen
CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide
Cyber Security Cooperative Research Centre
Adelaide
Australia, 5005
[email protected]
M. Ali Babar
CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide
Cyber Security Cooperative Research Centre
Adelaide
Australia, 5005
[email protected]
##
https://bugzilla.kernel.org/show_bug.cgi?id=200189https://github.com/lcytxw/bug_repro/tree/master/bug_200189https://github.com/torvalds/linux/commit/78c9c4dfbf8c04883941445a195276bb4bb92c76https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttps://usn.ubuntu.com/3847-1/https://usn.ubuntu.com/3847-2/https://usn.ubuntu.com/3847-3/https://usn.ubuntu.com/3848-1/https://usn.ubuntu.com/3848-2/https://usn.ubuntu.com/3849-1/https://usn.ubuntu.com/3849-2/https://bugzilla.kernel.org/show_bug.cgi?id=200189https://github.com/lcytxw/bug_repro/tree/master/bug_200189https://github.com/torvalds/linux/commit/78c9c4dfbf8c04883941445a195276bb4bb92c76https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttps://usn.ubuntu.com/3847-1/https://usn.ubuntu.com/3847-2/https://usn.ubuntu.com/3847-3/https://usn.ubuntu.com/3848-1/https://usn.ubuntu.com/3848-2/https://usn.ubuntu.com/3849-1/https://usn.ubuntu.com/3849-2/
2018-07-02
Published