CVE-2018-15471
published 2018-08-17CVE-2018-15471: An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
27.5th percentile
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.18.10-2 (bookworm) | linux 4.18.10-2 (bookworm) |
| linux | linux_kernel | >= 0 < 4.18.10-2 | 4.18.10-2 |
| linux | linux_kernel | >= 0 < 4.18.10-2 | 4.18.10-2 |
| linux | linux_kernel | >= 0 < 4.18.10-2 | 4.18.10-2 |
| linux | linux_kernel | >= 0 < 4.18.10-2 | 4.18.10-2 |
| linux | linux_kernel | >= 0 < 4.15.0-39.42 | 4.15.0-39.42 |
| linux | linux_kernel | >= 4.10 < 4.14.76 | 4.14.76 |
| linux | linux_kernel | >= 4.15 < 4.18.14 | 4.18.14 |
| linux | linux_kernel | >= 4.7 < 4.9.133 | 4.9.133 |
| xen | xen | <= 4.11.0 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2018-11-14
CVE-2018-15471 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Felix Wilhelm discovered that the Xen netback driver in the Linux kernel
did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virt
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2018-11-14·CVSS 7.8
CVE-2017-13168 [HIGH] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Felix Wilhelm discovered that the Xen netback driver in the Linux kernel
did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-15471)
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
It was discovered that an integer overflow existed in the CD-ROM driver of
the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-16
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-11-14·CVSS 7.8
CVE-2017-13168 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Felix Wilhelm discovered that the Xen netback driver in the Linux kernel
did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-15471)
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
It was discovered that an integer overflow existed in the CD-ROM driver of
the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-16658)
It
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-11-14·CVSS 7.8
CVE-2017-13168 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3820-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Felix Wilhelm discovered that the Xen netback driver in the Linux kernel
did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-15471)
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
priv
Red Hat
kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270)
vendor_redhat·2018-08-14·CVSS 7.8
CVE-2018-15471 [HIGH] CWE-20 kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270)
kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270)
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.
A flaw in the netback module allowed frontends to control mappi
Debian
CVE-2018-15471: linux - An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/ha...
vendor_debian·2018·CVSS 7.8
CVE-2018-15471 [HIGH] CVE-2018-15471: linux - An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/ha...
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.
Scope: local
bookworm: resolved (fixed in 4.18.10-2)
bullseye: resolved (fixed in 4.18.10-2)
forky: resolved (fixed in 4.18.10-2)
sid: resolve
GHSA
GHSA-qv83-77rj-635j: An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash
ghsa_unreviewed·2022-05-13
CVE-2018-15471 [HIGH] CWE-125 GHSA-qv83-77rj-635j: An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.
OSV
linux-azure vulnerabilities
osv·2018-11-14·CVSS 7.8
CVE-2018-15471 [HIGH] linux-azure vulnerabilities
linux-azure vulnerabilities
Felix Wilhelm discovered that the Xen netback driver in the Linux kernel
did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-15471)
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
It was discovered that an integer overflow existed in the CD-ROM driver of
the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-16658)
It was discovered that an integer overflow existed in the HID Bluetooth
impl
OSV
linux-hwe, linux-azure, linux-gcp vulnerabilities
osv·2018-11-14·CVSS 7.8
[HIGH] linux-hwe, linux-azure, linux-gcp vulnerabilities
linux-hwe, linux-azure, linux-gcp vulnerabilities
USN-3820-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Felix Wilhelm discovered that the Xen netback driver in the Linux kernel
did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-15471)
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
It was discovered that an intege
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2018-11-14·CVSS 7.8
CVE-2018-15471 [HIGH] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
Felix Wilhelm discovered that the Xen netback driver in the Linux kernel
did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-15471)
It was discovered that the generic SCSI driver in the Linux kernel did not
properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate
privileges. (CVE-2017-13168)
It was discovered that an integer overflow existed in the CD-ROM driver of
the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-16658)
It was disc
Kernel
xen-netback: fix input validation in xenvif_set_hash_mapping()
kernel_security·2018-09-25·CVSS 7.8
CVE-2018-15471 [HIGH] xen-netback: fix input validation in xenvif_set_hash_mapping()
xen-netback: fix input validation in xenvif_set_hash_mapping()
Both len and off are frontend specified values, so we need to make
sure there's no overflow when adding the two for the bounds check. We
also want to avoid undefined behavior and hence use off to index into
->hash.mapping[] only after bounds checking. This at the same time
allows to take care of not applying off twice for the bounds checking
against vif->num_queues.
It is also insufficient to bounds check copy_op.len, as this is len
truncated to 16 bits.
This is XSA-270 / CVE-2018-15471.
Reported-by: Felix Wilhelm
Signed-off-by: Jan Beulich
Reviewed-by: Paul Durrant
Tested-by: Paul Durrant
Cc: [email protected] [4.7 onwards]
Signed-off-by: David S. Miller
OSV
CVE-2018-15471: An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash
osv·2018-08-17·CVSS 7.8
CVE-2018-15471 [HIGH] CVE-2018-15471: An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-15471 kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270) [fedora-all]
bugzilla·2018-08-16·CVSS 7.8
CVE-2018-15471 [HIGH] CVE-2018-15471 kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270) [fedora-all]
CVE-2018-15471 kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-15471 xen: kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270) [fedora-all]
bugzilla·2018-08-16·CVSS 7.8
CVE-2018-15471 [HIGH] CVE-2018-15471 xen: kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270) [fedora-all]
CVE-2018-15471 xen: kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2018-15471 kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270)
bugzilla·2018-07-31·CVSS 7.8
CVE-2018-15471 [HIGH] CVE-2018-15471 kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270)
CVE-2018-15471 kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270)
Linux's netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation was missing or flawed. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.
Red Hat Enterprise Linux 5 is the only supported version of Red Hat Enterprise Linux that ships with Xen support, and does not include the relevant build time configuration that would enable this code to be included.
Additional information:
Xen security advisory - https://xenbits.xen.org/xs
http://xenbits.xen.org/xsa/advisory-270.htmlhttps://bugs.chromium.org/p/project-zero/issues/detail?id=1607https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://usn.ubuntu.com/3819-1/https://usn.ubuntu.com/3820-1/https://usn.ubuntu.com/3820-2/https://usn.ubuntu.com/3820-3/https://www.debian.org/security/2018/dsa-4313http://xenbits.xen.org/xsa/advisory-270.htmlhttps://bugs.chromium.org/p/project-zero/issues/detail?id=1607https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://usn.ubuntu.com/3819-1/https://usn.ubuntu.com/3820-1/https://usn.ubuntu.com/3820-2/https://usn.ubuntu.com/3820-3/https://www.debian.org/security/2018/dsa-4313
2018-08-17
Published