CVE-2018-19854
published 2018-12-04CVE-2018-19854: An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration…
PriorityP421medium4.7CVSS 3.0
AVLACHPRLUINSUCHINAN
EPSS
0.43%
35.6th percentile
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.18.20-1 (bookworm) | linux 4.18.20-1 (bookworm) |
| linux | linux_kernel | < 4.19.3 | 4.19.3 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.18.20-1 | 4.18.20-1 |
| linux | linux_kernel | >= 0 < 4.15.0-46.49 | 4.15.0-46.49 |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv7.0HIGH
vendor_ubuntu5.5MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-328v-h46x-hhhx: An issue was discovered in the Linux kernel before 4
ghsa_unreviewed·2022-05-13·CVSS 2.1
CVE-2018-19854 [LOW] CWE-200 GHSA-328v-h46x-hhhx: An issue was discovered in the Linux kernel before 4
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
osv·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
USN-3901-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in the
Linux
OSV
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
osv·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in
the Linux kernel. A local attacker could use this to gain access to
services that cache authorizations. (CVE-2019-6133)
OSV
linux, linux-hwe regression
osv·2019-02-08·CVSS 7.0
[HIGH] linux, linux-hwe regression
linux, linux-hwe regression
USN-3878-1 fixed vulnerabilities in the Linux kernel. Unfortunately,
that update introduced a regression that could prevent systems with
certain graphics chipsets from booting. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested
OSV
linux-hwe vulnerabilities
osv·2019-01-29·CVSS 7.0
CVE-2018-14625 [HIGH] linux-hwe vulnerabilities
linux-hwe vulnerabilities
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested KVM
virtualization is not enabled by default in Ubuntu kernels). A local
attacker in a guest VM could possibly use this to gain administrative
privileges in a host machine. (CVE-2018-16882)
Wei Wu discovered that the KVM implementation in the Linux kernel did not
properly en
OSV
CVE-2018-19854: An issue was discovered in the Linux kernel before 4
osv·2018-12-04·CVSS 2.1
CVE-2018-19854 [LOW] CVE-2018-19854: An issue was discovered in the Linux kernel before 4
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in
the Linux kernel. A local attacker could use this to gain access to
services that cache authorizations. (CVE-2019-6133)
Instructions: After a standard system update you need to reboot your computer to
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3901-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the for
Ubuntu
Linux kernel regression
vendor_ubuntu·2019-02-08·CVSS 5.3
[MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: USN-3878-1 introduced a regression in the Linux kernel.
USN-3878-1 fixed vulnerabilities in the Linux kernel. Unfortunately,
that update introduced a regression that could prevent systems with
certain graphics chipsets from booting. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling inte
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2019-02-07·CVSS 5.3
CVE-2018-14625 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested KVM
virtualization is not enabled by default in Ubuntu kernels). A local
attacker in a guest VM could possibly use this to gain administrative
privileges in a host machine. (CVE-2018-16882)
W
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-02-04·CVSS 5.3
CVE-2018-14625 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested KVM
virtualization is not enabled by default in Ubuntu kernels). A local
attacker in a guest VM could possibly use this to gain administrative
privileges in a host machine. (CVE-2018-16882)
Wei Wu di
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-01-29·CVSS 5.3
CVE-2018-14625 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the vsock address family
implementation of the Linux kernel that could lead to a use-after-free
condition. A local attacker in a guest virtual machine could use this to
expose sensitive information (host machine kernel memory). (CVE-2018-14625)
Cfir Cohen discovered that a use-after-free vulnerability existed in the
KVM implementation of the Linux kernel, when handling interrupts in
environments where nested virtualization is in use (nested KVM
virtualization is not enabled by default in Ubuntu kernels). A local
attacker in a guest VM could possibly use this to gain administrative
privileges in a host machine. (CVE-2018-16882)
Wei
Red Hat
kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
vendor_redhat·2018-11-03·CVSS 2.1
CVE-2018-19854 [LOW] CWE-200 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
An issue was discovered in the Linux kernel in the crypto_report_one() and related functions in the crypto/crypto_user.c (the crypto user configuration API) which do not fully initialize structures that are copied to userspace, potentially leaking se
Debian
CVE-2018-19854: linux - An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() a...
vendor_debian·2018·CVSS 2.1
CVE-2018-19854 [LOW] CVE-2018-19854: linux - An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() a...
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
Scope: local
bookworm: resolved (fixed in 4.18.20-1)
bullseye: resolved (fixed in 4.18.20-1)
forky: resolved (fixed in 4.18.20-1)
sid: resolved (fixed in 4.18.20-1)
trixie: resolved (fixed in 4.18.20-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19854 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c [fedora-all]
bugzilla·2018-12-10·CVSS 4.7
CVE-2018-19854 [MEDIUM] CVE-2018-19854 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c [fedora-all]
CVE-2018-19854 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2018-19854 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
bugzilla·2018-12-06·CVSS 4.7
CVE-2018-19854 [MEDIUM] CVE-2018-19854 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
CVE-2018-19854 kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
An issue was discovered in the Linux kernel in the crypto_report_one() and related functions in the crypto/crypto_user.c (the crypto user configuration API) which do not fully initialize structures that are copied to userspace, potentially leaking sensitive kernel memory content to a userspace.
References:
https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.3
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f43f39958beb206b53292801e216d9b8a660f087
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1657882]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f43f39958beb206b53292801e216d9b8a660f087https://access.redhat.com/errata/RHSA-2019:3309https://access.redhat.com/errata/RHSA-2019:3517https://github.com/torvalds/linux/commit/f43f39958beb206b53292801e216d9b8a660f087https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.3https://usn.ubuntu.com/3872-1/https://usn.ubuntu.com/3878-1/https://usn.ubuntu.com/3878-2/https://usn.ubuntu.com/3901-1/https://usn.ubuntu.com/3901-2/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f43f39958beb206b53292801e216d9b8a660f087https://access.redhat.com/errata/RHSA-2019:3309https://access.redhat.com/errata/RHSA-2019:3517https://github.com/torvalds/linux/commit/f43f39958beb206b53292801e216d9b8a660f087https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.3https://usn.ubuntu.com/3872-1/https://usn.ubuntu.com/3878-1/https://usn.ubuntu.com/3878-2/https://usn.ubuntu.com/3901-1/https://usn.ubuntu.com/3901-2/
2018-12-04
Published