CVE-2018-18445
published 2018-10-17CVE-2018-18445: In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.53%
41.8th percentile
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.18.20-1 (bookworm) | linux 4.18.20-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.15.0-43.46 | 4.15.0-43.46 |
| linux | linux_kernel | >= 4.14.9 < 4.14.75 | 4.14.75 |
| linux | linux_kernel | >= 4.15 < 4.18.13 | 4.18.13 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus d
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered th
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-03·CVSS 5.5
CVE-2018-17972 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the procfs file system implementation in the
Linux kernel did not properly restrict the ability to inspect the kernel
stack of an arbitrary task. A local attacker could use this to expose
sensitive information. (CVE-2018-17972)
Jann Horn discovered that the mremap() system call in the Linux kernel did
not properly flush the TLB when completing, potentially leaving access to a
physical page after it has been released to the page allocator. A local
attacker could use this to cause a denial of service (system crash), expose
sensitive information, or possibly execute arbitrary code. (CVE-2018-18281)
It was discovered that the BPF verifier in the Linux kernel did no
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2018-11-30·CVSS 5.5
CVE-2018-17972 [MEDIUM] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the procfs file system implementation in the
Linux kernel did not properly restrict the ability to inspect the kernel
stack of an arbitrary task. A local attacker could use this to expose
sensitive information. (CVE-2018-17972)
Jann Horn discovered that the mremap() system call in the Linux kernel did
not properly flush the TLB when completing, potentially leaving access to a
physical page after it has been released to the page allocator. A local
attacker could use this to cause a denial of service (system crash), expose
sensitive information, or possibly execute arbitrary code. (CVE-2018-18281)
It was discovered that the BPF verifier in the Linux kernel
Red Hat
kernel: Faulty computation of numberic bounds in the BPF verifier
vendor_redhat·2018-10-05·CVSS 7.8
CVE-2018-18445 [HIGH] CWE-125 kernel: Faulty computation of numberic bounds in the BPF verifier
kernel: Faulty computation of numberic bounds in the BPF verifier
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
A security flaw was found in the Linux kernel in the adjust_scalar_min_max_vals() function in kernel/bpf/verifier.c. A faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because this function mishandles 32-bit right shifts. A local unprivileged user cannot leverage this flaw, but as a privileged user ("root") this can lead to a system panic and a denial of service or other unspecified impact. Due to the nature of the f
Debian
CVE-2018-18445: linux - In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, f...
vendor_debian·2018·CVSS 7.8
CVE-2018-18445 [HIGH] CVE-2018-18445: linux - In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, f...
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
Scope: local
bookworm: resolved (fixed in 4.18.20-1)
bullseye: resolved (fixed in 4.18.20-1)
forky: resolved (fixed in 4.18.20-1)
sid: resolved (fixed in 4.18.20-1)
trixie: resolved (fixed in 4.18.20-1)
GHSA
GHSA-c3vm-qh5c-27gq: In the Linux kernel 4
ghsa_unreviewed·2022-05-13
CVE-2018-18445 [HIGH] CWE-125 GHSA-c3vm-qh5c-27gq: In the Linux kernel 4
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
OSV
linux-azure vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] linux-azure vulnerabilities
linux-azure vulnerabilities
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
osv·2018-12-20·CVSS 7.8
[HIGH] linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerabili
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that the YURE
OSV
CVE-2018-18445: In the Linux kernel 4
osv·2018-10-17·CVSS 7.8
CVE-2018-18445 [HIGH] CVE-2018-18445: In the Linux kernel 4
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b799207e1e1816b09e7a5920fbb2d5fcf6edd681https://access.redhat.com/errata/RHSA-2019:0512https://access.redhat.com/errata/RHSA-2019:0514https://bugs.chromium.org/p/project-zero/issues/detail?id=1686https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.75https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.13https://github.com/torvalds/linux/commit/b799207e1e1816b09e7a5920fbb2d5fcf6edd681https://support.f5.com/csp/article/K38456756https://usn.ubuntu.com/3832-1/https://usn.ubuntu.com/3835-1/https://usn.ubuntu.com/3847-1/https://usn.ubuntu.com/3847-2/https://usn.ubuntu.com/3847-3/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b799207e1e1816b09e7a5920fbb2d5fcf6edd681https://access.redhat.com/errata/RHSA-2019:0512https://access.redhat.com/errata/RHSA-2019:0514https://bugs.chromium.org/p/project-zero/issues/detail?id=1686https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.75https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.13https://github.com/torvalds/linux/commit/b799207e1e1816b09e7a5920fbb2d5fcf6edd681https://support.f5.com/csp/article/K38456756https://usn.ubuntu.com/3832-1/https://usn.ubuntu.com/3835-1/https://usn.ubuntu.com/3847-1/https://usn.ubuntu.com/3847-2/https://usn.ubuntu.com/3847-3/
2018-10-17
Published