CVE-2018-20449
published 2019-04-04CVE-2018-20449: The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading…
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.42%
34.7th percentile
The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.15.4-1 (bookworm) | linux 4.15.4-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cx2c-r978-5vg7: The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg
ghsa_unreviewed·2022-05-14
CVE-2018-20449 [MEDIUM] CWE-200 GHSA-cx2c-r978-5vg7: The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg
The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file.
OSV
CVE-2018-20449: The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg
osv·2019-04-04·CVSS 5.5
CVE-2018-20449 [MEDIUM] CVE-2018-20449: The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg
The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file.
Red Hat
kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure
vendor_redhat·2019-01-22·CVSS 5.5
CVE-2018-20449 [MEDIUM] CWE-200 kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure
kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure
The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file.
The hidma_chan_stats() function in the drivers/dma/qcom/hidma_dbg.c file in the Linux kernel allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file. By default, the debugfs filesystem access is restricted so only a privileged user can access it.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Pa
Debian
CVE-2018-20449: linux - The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kerne...
vendor_debian·2018·CVSS 5.5
CVE-2018-20449 [MEDIUM] CVE-2018-20449: linux - The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kerne...
The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file.
Scope: local
bookworm: resolved (fixed in 4.15.4-1)
bullseye: resolved (fixed in 4.15.4-1)
forky: resolved (fixed in 4.15.4-1)
sid: resolved (fixed in 4.15.4-1)
trixie: resolved (fixed in 4.15.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20449 kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure
bugzilla·2019-04-05·CVSS 5.5
CVE-2018-20449 [MEDIUM] CVE-2018-20449 kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure
CVE-2018-20449 kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure
The hidma_chan_stats() function in the drivers/dma/qcom/hidma_dbg.c file in the Linux kernel allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file. By default debugfs filesystem access is restricted, so only a privileged user can access it.
References:
https://www.mail-archive.com/[email protected]/msg03808.html
Upstream patches:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ad67b74d2469d9b82aaa572d76474c95bc484d57
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=91efafb1dd8f471177a3dddb4841d75d3df1cc46
Discussion:
Cr
Bugzilla
CVE-2018-20449 kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure [fedora-all]
bugzilla·2019-04-05·CVSS 5.5
CVE-2018-20449 [MEDIUM] CVE-2018-20449 kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure [fedora-all]
CVE-2018-20449 kernel: reading "callback=" lines in a debugfs file in drivers/dma/qcom/hidma_dbg.c results in information disclosure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg c
https://elixir.bootlin.com/linux/v4.14.90/source/drivers/dma/qcom/hidma_dbg.c#L92https://security.netapp.com/advisory/ntap-20190502-0002/https://www.mail-archive.com/debian-security-tracker%40lists.debian.org/msg03808.htmlhttps://elixir.bootlin.com/linux/v4.14.90/source/drivers/dma/qcom/hidma_dbg.c#L92https://security.netapp.com/advisory/ntap-20190502-0002/https://www.mail-archive.com/debian-security-tracker%40lists.debian.org/msg03808.html
2019-04-04
Published