CVE-2018-14678
published 2018-07-28CVE-2018-14678: An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.7th percentile
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.17.14-1 (bookworm) | linux 4.17.14-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.17.14-1 | 4.17.14-1 |
| linux | linux_kernel | >= 0 < 4.17.14-1 | 4.17.14-1 |
| linux | linux_kernel | >= 0 < 4.17.14-1 | 4.17.14-1 |
| linux | linux_kernel | >= 0 < 4.17.14-1 | 4.17.14-1 |
| linux | linux_kernel | >= 0 < 4.15.0-47.50 | 4.15.0-47.50 |
| linux | linux_kernel | >= 4.14.21 < 4.14.61 | 4.14.61 |
| linux | linux_kernel | >= 4.15.5 < 4.17.13 | 4.17.13 |
| xen | xen | <= 4.11.0 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mmph-rg95-j757: An issue was discovered in the Linux kernel through 4
ghsa_unreviewed·2022-05-13
CVE-2018-14678 [HIGH] CWE-665 GHSA-mmph-rg95-j757: An issue was discovered in the Linux kernel through 4
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.
OSV
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
osv·2019-04-02·CVSS 7.8
CVE-2018-14678 [HIGH] linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
M. Vefa Bicakci and Andy Lutomirski discovered that the kernel did not
properly set up all arguments to an error handler callback used when
running as a paravirtualized guest. An unprivileged attacker in a
paravirtualized guest VM could use this to cause a denial of service (guest
VM crash). (CVE-2018-14678)
It was discovered that the KVM implementation in the Linux kernel on ARM
64bit processors did not properly handle some ioctls. An attacker with the
privilege to create KVM-based virtual machines could use this to cause a
denial of service (host system crash) or execute arbitrary code in the
host. (CVE-2018-18021)
Mathias Payer and Hui Peng discovered a use-after-free vulnerability in the
Ad
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
osv·2019-04-02·CVSS 7.8
[HIGH] linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
USN-3931-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS and for the Linux Azure kernel for Ubuntu 14.04 LTS.
M. Vefa Bicakci and Andy Lutomirski discovered that the kernel did not
properly set up all arguments to an error handler callback used when
running as a paravirtualized guest. An unprivileged attacker in a
paravirtualized guest VM could use this to cause a denial of service (guest
VM crash). (CVE-2018-14678)
It was discovered that the KVM implementation in the Linux kernel on ARM
64bit processors did not properly handle some ioctls. An attacker with
OSV
CVE-2018-14678: An issue was discovered in the Linux kernel through 4
osv·2018-07-28·CVSS 7.8
CVE-2018-14678 [HIGH] CVE-2018-14678: An issue was discovered in the Linux kernel through 4
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-04-02·CVSS 7.8
CVE-2018-14678 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3931-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS and for the Linux Azure kernel for Ubuntu 14.04 LTS.
M. Vefa Bicakci and Andy Lutomirski discovered that the kernel did not
properly set up all arguments to an error handler callback used when
running as a paravirtualized guest. An unprivileged attacker in a
paravirtualized guest VM could use this to cause a denial of service (guest
VM crash). (CVE-2018-14678)
It was discovered that the KVM implementation in the Linux kernel on ARM
64bit processors did not properly handle
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-04-02·CVSS 7.8
CVE-2018-14678 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
M. Vefa Bicakci and Andy Lutomirski discovered that the kernel did not
properly set up all arguments to an error handler callback used when
running as a paravirtualized guest. An unprivileged attacker in a
paravirtualized guest VM could use this to cause a denial of service (guest
VM crash). (CVE-2018-14678)
It was discovered that the KVM implementation in the Linux kernel on ARM
64bit processors did not properly handle some ioctls. An attacker with the
privilege to create KVM-based virtual machines could use this to cause a
denial of service (host system crash) or execute arbitrary code in the
host. (CVE-2018-18021)
Mathias Payer and Hui Peng discovered a use-after-free vulnerability i
Red Hat
xen: Uninitialized state in x86 PV failsafe callback path (XSA-274)
vendor_redhat·2018-07-25·CVSS 7.8
CVE-2018-14678 [HIGH] CWE-119 xen: Uninitialized state in x86 PV failsafe callback path (XSA-274)
xen: Uninitialized state in x86 PV failsafe callback path (XSA-274)
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.
Statement: This issue only affects guests running as Xen paravirtualized (PV) guests. Starting with Red Hat Enterprise Linux 7 onwards running Red Hat Enterprise Linux installations as Xen PV guests is not supported.
Package: kernel (Red Hat Enterprise Linux 5) - Out of support scope
Package: kernel-xen (Red Hat Enterprise Linux
Debian
CVE-2018-14678: linux - An issue was discovered in the Linux kernel through 4.17.11, as used in Xen thro...
vendor_debian·2018·CVSS 7.8
CVE-2018-14678 [HIGH] CVE-2018-14678: linux - An issue was discovered in the Linux kernel through 4.17.11, as used in Xen thro...
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.
Scope: local
bookworm: resolved (fixed in 4.17.14-1)
bullseye: resolved (fixed in 4.17.14-1)
forky: resolved (fixed in 4.17.14-1)
sid: resolved (fixed in 4.17.14-1)
trixie: resolved (fixed in 4.17.14-1)
No detection rules found.
No public exploits indexed.
arXiv
Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud
arxiv_fulltext·2020-09-03
Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud
Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud
Hootan Alavizadeh1, Hooman Alavizadeh2 and Julian Jang-Jaccard2
1 Computer Engineering Department,
Imam Reza International University, Mashhah, Iran.
Email: [email protected]
2 School of Natural and Computational Sciences,
Massey University, Auckland, New Zealand.
Email: \h.alavizadeh,J.Jang-jaccard\@massey.ac.nz
## Abstract
The cloud model allows many enterprises able to outsource computing resources at an affordable price without having to commit the expense upfront. Although the cloud providers are responsible for the security of the cloud, there are still many security concerns due to inherently complex model the cloud providers operate on (e.g.,multi-tenancy). In addition, the ente
Bugzilla
CVE-2018-14678 xen: Uninitialized state in x86 PV failsafe callback path (XSA-274)
bugzilla·2018-07-25·CVSS 7.8
CVE-2018-14678 [HIGH] CVE-2018-14678 xen: Uninitialized state in x86 PV failsafe callback path (XSA-274)
CVE-2018-14678 xen: Uninitialized state in x86 PV failsafe callback path (XSA-274)
Xen Security Advisory XSA-274
Linux: Uninitialized state in PV syscall return path
ISSUE DESCRIPTION
Linux has a `failsafe` callback, invoked by Xen under certain
conditions. Normally in this failsafe callback, error_entry is paired
with error_exit; and error_entry uses %ebx to communicate to
error_exit whether to use the user or kernel return path.
Unfortunately, on 64-bit PV Xen on x86, error_exit is called without
error_entry being called first, leaving %ebx with an invalid value.
IMPACT
A rogue user-space program could crash a guest kernel. Privilege
escalation cannot be ruled out.
VULNERABLE SYSTEMS
Only 64-bit x86 PV Linux systems are vulnerable.
All versions of Linux are vulnerable.
MITIGAT
Bugzilla
CVE-2018-14678 xen: Uninitialized state in PV syscall return path (XSA-274) [fedora-all]
bugzilla·2018-07-25·CVSS 7.8
CVE-2018-14678 [HIGH] CVE-2018-14678 xen: Uninitialized state in PV syscall return path (XSA-274) [fedora-all]
CVE-2018-14678 xen: Uninitialized state in PV syscall return path (XSA-274) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2018-11357 wireshark: Uncontrolled Resource Consumption in epan/tvbuff.c
bugzilla·2018-05-23·CVSS 7.5
CVE-2018-11357 [HIGH] CVE-2018-11357 wireshark: Uncontrolled Resource Consumption in epan/tvbuff.c
CVE-2018-11357 wireshark: Uncontrolled Resource Consumption in epan/tvbuff.c
A flaw was found in Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. This was addressed in epan/tvbuff.c by rejecting negative lengths.
References:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14678
https://www.wireshark.org/security/wnpa-sec-2018-28.html
Upstream patch:
https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=ab8a33ef083b9732c89117747a83a905a676faf6
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1581754]
---
http://www.securityfocus.com/bid/104924http://www.securitytracker.com/id/1041397https://lists.debian.org/debian-lts-announce/2018/10/msg00003.htmlhttps://usn.ubuntu.com/3931-1/https://usn.ubuntu.com/3931-2/https://www.debian.org/security/2018/dsa-4308https://xenbits.xen.org/xsa/advisory-274.htmlhttp://www.securityfocus.com/bid/104924http://www.securitytracker.com/id/1041397https://lists.debian.org/debian-lts-announce/2018/10/msg00003.htmlhttps://usn.ubuntu.com/3931-1/https://usn.ubuntu.com/3931-2/https://www.debian.org/security/2018/dsa-4308https://xenbits.xen.org/xsa/advisory-274.html
2018-07-28
Published