CVE-2018-19854Sensitive Information Exposure in Kernel

Severity
4.7MEDIUMNVD
OSV7.0OSV5.5OSV2.1
EPSS
0.1%
top 83.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 4
Latest updateMay 13

Description

An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel< 4.19.3
Debianlinux/linux_kernel< 4.18.20-1+3
Ubuntulinux/linux_kernel< 4.15.0-46.49
debiandebian/linux< linux 4.18.20-1 (bookworm)

Also affects: Ubuntu Linux 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

6
GHSA
GHSA-328v-h46x-hhhx: An issue was discovered in the Linux kernel before 42022-05-13
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities2019-03-05
OSV
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities2019-03-05
OSV
linux, linux-hwe regression2019-02-08
OSV
linux-hwe vulnerabilities2019-01-29

📋Vendor Advisories

8
Ubuntu
Linux kernel vulnerabilities2019-03-05
Ubuntu
Linux kernel (HWE) vulnerabilities2019-03-05
Ubuntu
Linux kernel regression2019-02-08
Ubuntu
Linux kernel (Azure) vulnerabilities2019-02-07
Ubuntu
Linux kernel vulnerabilities2019-02-04

💬Community

2
Bugzilla
CVE-2018-19854 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c [fedora-all]2018-12-10
Bugzilla
CVE-2018-19854 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c2018-12-06