CVE-2018-18397
published 2018-12-12CVE-2018-18397: The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local…
PriorityP428medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EXPLOIT
EPSS
0.51%
40.1th percentile
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.19.9-1 (bookworm) | linux 4.19.9-1 (bookworm) |
| linux | linux_kernel | < 4.19.7 | 4.19.7 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.15.0-46.49 | 4.15.0-46.49 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-03-06·CVSS 7.0
CVE-2018-16880 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3903-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 18.10 for Ubuntu 18.04 LTS.
Jason Wang discovered that the vhost net driver in the Linux kernel
contained an out of bounds write vulnerability. An attacker in a guest
virtual machine could use this to cause a denial of service (host system
crash) or possibly execute arbitrary code in the host kernel.
(CVE-2018-16880)
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-20
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-03-06·CVSS 7.0
CVE-2018-16880 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jason Wang discovered that the vhost net driver in the Linux kernel
contained an out of bounds write vulnerability. An attacker in a guest
virtual machine could use this to cause a denial of service (host system
crash) or possibly execute arbitrary code in the host kernel.
(CVE-2018-16880)
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
Jann Horn discovered a race condition in the fork() system call in the
Linux kernel. A local attacker could use this to gain access to services
that cache authorizations. (CVE-2019-6133)
Instructions:
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in
the Linux kernel. A local attacker could use this to gain access to
services that cache authorizations. (CVE-2019-6133)
Instructions: After a standard system update you need to reboot your computer to
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3901-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the for
Red Hat
kernel: userfaultfd bypasses tmpfs file permissions
vendor_redhat·2018-11-26·CVSS 5.5
CVE-2018-18397 [MEDIUM] CWE-20 kernel: userfaultfd bypasses tmpfs file permissions
kernel: userfaultfd bypasses tmpfs file permissions
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
A flaw was found in the Linux kernel with files on tmpfs and hugetlbfs. An attacker is able to bypass file permissions on filesystems mounted with tmpfs/hugetlbs to modify a file and possibly disrupt normal system behavior. At this time there is an understanding there is no crash or privilege escalation but the impact of modifications on these filesystems of files in production systems may have adverse affect
Debian
CVE-2018-18397: linux - The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles acce...
vendor_debian·2018·CVSS 5.5
CVE-2018-18397 [MEDIUM] CVE-2018-18397: linux - The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles acce...
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
Scope: local
bookworm: resolved (fixed in 4.19.9-1)
bullseye: resolved (fixed in 4.19.9-1)
forky: resolved (fixed in 4.19.9-1)
sid: resolved (fixed in 4.19.9-1)
trixie: resolved (fixed in 4.19.9-1)
GHSA
GHSA-7cx6-7887-9rwv: The userfaultfd implementation in the Linux kernel before 4
ghsa_unreviewed·2022-05-13
CVE-2018-18397 [MEDIUM] CWE-863 GHSA-7cx6-7887-9rwv: The userfaultfd implementation in the Linux kernel before 4
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
OSV
linux-hwe, linux-azure vulnerabilities
osv·2019-03-06·CVSS 7.0
[HIGH] linux-hwe, linux-azure vulnerabilities
linux-hwe, linux-azure vulnerabilities
USN-3903-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 18.10 for Ubuntu 18.04 LTS.
Jason Wang discovered that the vhost net driver in the Linux kernel
contained an out of bounds write vulnerability. An attacker in a guest
virtual machine could use this to cause a denial of service (host system
crash) or possibly execute arbitrary code in the host kernel.
(CVE-2018-16880)
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
Jann Horn discovered a race condition in the fork() system
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
osv·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
USN-3901-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in the
Linux
OSV
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
osv·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in
the Linux kernel. A local attacker could use this to gain access to
services that cache authorizations. (CVE-2019-6133)
OSV
CVE-2018-18397: The userfaultfd implementation in the Linux kernel before 4
osv·2018-12-12·CVSS 5.5
CVE-2018-18397 [MEDIUM] CVE-2018-18397: The userfaultfd implementation in the Linux kernel before 4
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
No detection rules found.
Bugzilla
CVE-2018-18397 kernel: userfaultfd bypasses tmpfs file permissions [fedora-all]
bugzilla·2018-12-12·CVSS 5.5
CVE-2018-18397 [MEDIUM] CVE-2018-18397 kernel: userfaultfd bypasses tmpfs file permissions [fedora-all]
CVE-2018-18397 kernel: userfaultfd bypasses tmpfs file permissions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2018-18397 kernel: userfaultfd bypasses tmpfs file permissions
bugzilla·2018-10-22·CVSS 5.5
CVE-2018-18397 [MEDIUM] CVE-2018-18397 kernel: userfaultfd bypasses tmpfs file permissions
CVE-2018-18397 kernel: userfaultfd bypasses tmpfs file permissions
A flaw was found in the Linux kernel with files on tmpfs and hugetlbfs. An attacker is able to bypass file permissions on filesystems mounted with tmpfs/hugetlbs to modify a file and possibly disrupt normal system behaviour.
At this time there is an understanding there is no crash or priviledge escalation but the impact of modifications on these filesystems of files in production systems may have adverse affects.
A suggested upstream patch:
https://lore.kernel.org/lkml/[email protected]/T/#u
An upstream patchset:
9e368259ad988356c4c95150fafd1a06af095d98 userfaultfd: use ENOENT instead of EFAULT if the atomic copy user fails
5b51072e97d587186c2f5390c8c9c1fb7e179505 userfaultfd: shmem: allocate
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=29ec90660d68bbdd69507c1c8b4e33aa299278b1https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0163https://access.redhat.com/errata/RHSA-2019:0202https://access.redhat.com/errata/RHSA-2019:0324https://access.redhat.com/errata/RHSA-2019:0831https://bugs.chromium.org/p/project-zero/issues/detail?id=1700https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.87https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.7https://github.com/torvalds/linux/commit/29ec90660d68bbdd69507c1c8b4e33aa299278b1https://usn.ubuntu.com/3901-1/https://usn.ubuntu.com/3901-2/https://usn.ubuntu.com/3903-1/https://usn.ubuntu.com/3903-2/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=29ec90660d68bbdd69507c1c8b4e33aa299278b1https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0163https://access.redhat.com/errata/RHSA-2019:0202https://access.redhat.com/errata/RHSA-2019:0324https://access.redhat.com/errata/RHSA-2019:0831https://bugs.chromium.org/p/project-zero/issues/detail?id=1700https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.87https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.7https://github.com/torvalds/linux/commit/29ec90660d68bbdd69507c1c8b4e33aa299278b1https://usn.ubuntu.com/3901-1/https://usn.ubuntu.com/3901-2/https://usn.ubuntu.com/3903-1/https://usn.ubuntu.com/3903-2/
2018-12-12
Published