CVE-2018-14625
published 2018-09-10CVE-2018-14625: A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition…
PriorityP430high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.33%
25.9th percentile
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.19.9-1 (bookworm) | linux 4.19.9-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.15.0-44.47 | 4.15.0-44.47 |
| linux | linux_kernel | >= 0 < 4.15.0-45.48 | 4.15.0-45.48 |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jrcc-3vp8-hghg: A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest
ghsa_unreviewed·2022-05-14
CVE-2018-14625 [HIGH] CWE-362 GHSA-jrcc-3vp8-hghg: A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
OSV
linux, linux-hwe regression
osv·2019-02-08·CVSS 7.0
[HIGH] linux, linux-hwe regression
linux, linux-hwe regression
USN-3878-1 fixed vulnerabilities in the Linux kernel. Unfortunately,
that update introduced a regression that could prevent systems with
certain graphics chipsets from booting. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested
OSV
linux-azure vulnerabilities
osv·2019-02-07·CVSS 5.5
CVE-2018-10876 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
ext4 filesystem implementation in the Linux kernel. An attacker could use
this to c
OSV
linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2019-02-04·CVSS 5.5
CVE-2018-10876 [MEDIUM] linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
ext4 filesystem implementation in the
OSV
linux-hwe, linux-aws-hwe, linux-gcp vulnerabilities
osv·2019-02-04·CVSS 5.5
[MEDIUM] linux-hwe, linux-aws-hwe, linux-gcp vulnerabilities
linux-hwe, linux-aws-hwe, linux-gcp vulnerabilities
USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial
OSV
linux regression
osv·2019-01-31·CVSS 5.5
[MEDIUM] linux regression
linux regression
USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. Unfortunately, that update introduced regressions with docking
station displays and mounting ext4 file systems with the meta_bg
option enabled. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to constr
OSV
linux vulnerabilities
osv·2019-01-29·CVSS 5.5
CVE-2018-10876 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
ext4 filesystem implementation in the Linux kernel. An attacker could use
this to constru
OSV
linux-hwe vulnerabilities
osv·2019-01-29·CVSS 7.0
CVE-2018-14625 [HIGH] linux-hwe vulnerabilities
linux-hwe vulnerabilities
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested KVM
virtualization is not enabled by default in Ubuntu kernels). A local
attacker in a guest VM could possibly use this to gain administrative
privileges in a host machine. (CVE-2018-16882)
Wei Wu discovered that the KVM implementation in the Linux kernel did not
properly en
Kernel
vhost/vsock: fix use-after-free in network stack callers
kernel_security·2018-11-05·CVSS 5.3
CVE-2018-14625 [MEDIUM] vhost/vsock: fix use-after-free in network stack callers
vhost/vsock: fix use-after-free in network stack callers
If the network stack calls .send_pkt()/.cancel_pkt() during .release(),
a struct vhost_vsock use-after-free is possible. This occurs because
.release() does not wait for other CPUs to stop using struct
vhost_vsock.
Switch to an RCU-enabled hashtable (indexed by guest CID) so that
.release() can wait for other CPUs by calling synchronize_rcu(). This
also eliminates vhost_vsock_lock acquisition in the data path so it
could have a positive effect on performance.
This is CVE-2018-14625 "kernel: use-after-free Read in vhost_transport_send_pkt".
Cc: [email protected]
Reported-and-tested-by: [email protected]
Reported-by: [email protected]
Reported-by: syzbot+d
OSV
CVE-2018-14625: A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest
osv·2018-09-10·CVSS 7.0
CVE-2018-14625 [HIGH] CVE-2018-14625: A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
Ubuntu
Linux kernel regression
vendor_ubuntu·2019-02-08·CVSS 5.3
[MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: USN-3878-1 introduced a regression in the Linux kernel.
USN-3878-1 fixed vulnerabilities in the Linux kernel. Unfortunately,
that update introduced a regression that could prevent systems with
certain graphics chipsets from booting. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling inte
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2019-02-07·CVSS 5.0
CVE-2018-10876 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
e
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2019-02-07·CVSS 5.3
CVE-2018-14625 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested KVM
virtualization is not enabled by default in Ubuntu kernels). A local
attacker in a guest VM could possibly use this to gain administrative
privileges in a host machine. (CVE-2018-16882)
W
Ubuntu
Linux kernel (AWS, GCP, KVM, OEM, Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2019-02-04·CVSS 5.0
CVE-2018-10876 [MEDIUM] Linux kernel (AWS, GCP, KVM, OEM, Raspberry Pi 2) vulnerabilities
Title: Linux kernel (AWS, GCP, KVM, OEM, Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write v
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-02-04·CVSS 5.3
CVE-2018-14625 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested KVM
virtualization is not enabled by default in Ubuntu kernels). A local
attacker in a guest VM could possibly use this to gain administrative
privileges in a host machine. (CVE-2018-16882)
Wei Wu di
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-02-04·CVSS 5.0
CVE-2018-10876 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malici
Ubuntu
Linux kernel regression
vendor_ubuntu·2019-01-31·CVSS 5.0
[MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: Multiple regressions were fixed in the Linux kernel.
USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. Unfortunately, that update introduced regressions with docking
station displays and mounting ext4 file systems with the meta_bg
option enabled. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesy
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-01-29·CVSS 5.3
CVE-2018-14625 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested KVM
virtualization is not enabled by default in Ubuntu kernels). A local
attacker in a guest VM could possibly use this to gain administrative
privileges in a host machine. (CVE-2018-16882)
Wei
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-01-29·CVSS 5.0
CVE-2018-10876 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Xu discovered that a use-after-free vulnerability existed in the ext4
filesystem implementation in the Linux kernel. An attacker could use this
to construct a malicious ext4 image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2018-10876, CVE-2018-10879)
Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct
a malicious ext4 image that, when mounted, could cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2018-10877)
Wen Xu discovered that an out-of-bounds write vulnerability existed in the
ext4 file
Red Hat
kernel: use-after-free Read in vhost_transport_send_pkt
vendor_redhat·2018-07-30·CVSS 5.3
CVE-2018-14625 [MEDIUM] CWE-362 kernel: use-after-free Read in vhost_transport_send_pkt
kernel: use-after-free Read in vhost_transport_send_pkt
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
A flaw was found where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly impersonate AF_VSOCK messages destined to other clients or leak kernel memory.
Package: kernel (Red Hat Enterpris
Debian
CVE-2018-14625: linux - A flaw was found in the Linux Kernel where an attacker may be able to have an un...
vendor_debian·2018·CVSS 5.3
CVE-2018-14625 [MEDIUM] CVE-2018-14625: linux - A flaw was found in the Linux Kernel where an attacker may be able to have an un...
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
Scope: local
bookworm: resolved (fixed in 4.19.9-1)
bullseye: resolved (fixed in 4.19.9-1)
forky: resolved (fixed in 4.19.9-1)
sid: resolved (fixed in 4.19.9-1)
trixie: resolved (fixed in 4.19.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14625 kernel: use-after-free Read in vhost_transport_send_pkt
bugzilla·2018-08-21·CVSS 5.3
CVE-2018-14625 [MEDIUM] CVE-2018-14625 kernel: use-after-free Read in vhost_transport_send_pkt
CVE-2018-14625 kernel: use-after-free Read in vhost_transport_send_pkt
A flaw was found in Linux Kernel in which an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
Introduced by:
https://github.com/torvalds/linux/commit/433fc58e6bf2c8bd97e57153ed28e64fd78207b8
References:
https://syzkaller.appspot.com/bug?extid=bd391451452fb0b93039
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1619847]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019
Bugzilla
CVE-2018-14625 kernel: use-after-free Read in vhost_transport_send_pkt [fedora-all]
bugzilla·2018-08-21·CVSS 5.3
CVE-2018-14625 [MEDIUM] CVE-2018-14625 kernel: use-after-free Read in vhost_transport_send_pkt [fedora-all]
CVE-2018-14625 kernel: use-after-free Read in vhost_transport_send_pkt [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
https://access.redhat.com/errata/RHSA-2019:2029https://access.redhat.com/errata/RHSA-2019:2043https://access.redhat.com/errata/RHSA-2019:4154https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14625https://lists.debian.org/debian-lts-announce/2019/05/msg00002.htmlhttps://syzkaller.appspot.com/bug?extid=bd391451452fb0b93039https://usn.ubuntu.com/3871-1/https://usn.ubuntu.com/3871-3/https://usn.ubuntu.com/3871-4/https://usn.ubuntu.com/3871-5/https://usn.ubuntu.com/3872-1/https://usn.ubuntu.com/3878-1/https://usn.ubuntu.com/3878-2/https://access.redhat.com/errata/RHSA-2019:2029https://access.redhat.com/errata/RHSA-2019:2043https://access.redhat.com/errata/RHSA-2019:4154https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14625https://lists.debian.org/debian-lts-announce/2019/05/msg00002.htmlhttps://syzkaller.appspot.com/bug?extid=bd391451452fb0b93039https://usn.ubuntu.com/3871-1/https://usn.ubuntu.com/3871-3/https://usn.ubuntu.com/3871-4/https://usn.ubuntu.com/3871-5/https://usn.ubuntu.com/3872-1/https://usn.ubuntu.com/3878-1/https://usn.ubuntu.com/3878-2/
2018-09-10
Published