CVE-2018-20836
published 2019-05-07CVE-2018-20836: An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in…
PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
5.11%
91.5th percentile
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.2.6-1 (bookworm) | linux 5.2.6-1 (bookworm) |
| f5 | traffix_signaling_delivery_controller | — | — |
| f5 | traffix_signaling_delivery_controller | — | — |
| linux | linux_kernel | < 3.16.72 | 3.16.72 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 4.4.0-157.185 | 4.4.0-157.185 |
| linux | linux_kernel | >= 3.17 < 3.18.140 | 3.18.140 |
| linux | linux_kernel | >= 3.19 < 4.4.180 | 4.4.180 |
| linux | linux_kernel | >= 4.10 < 4.14.118 | 4.14.118 |
| linux | linux_kernel | >= 4.15 < 4.19.42 | 4.19.42 |
| linux | linux_kernel | >= 4.5 < 4.9.175 | 4.9.175 |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| netapp | vasa_provider_for_clustered_data_ontap | >= 7.2 | — |
| netapp | virtual_storage_console | >= 7.2 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-07-25·CVSS 8.1
CVE-2018-20836 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel. A local attacker could possibly
use this to cause a denial of service (system crash) or execute arbitrary
code. (CVE-2018-20836)
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)
It was discovered that the Bluetooth Human Interface Device Protocol (HIDP)
implementation in the Linux kernel did not properly verify strings were
NULL terminated in certain situations. A local attacker could use this
Red Hat
kernel: race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c leads to use-after-free
vendor_redhat·2018-09-25·CVSS 8.1
CVE-2018-20836 [HIGH] CWE-366 kernel: race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c leads to use-after-free
kernel: race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c leads to use-after-free
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
A flaw was found in the Linux kernel’s implementation of the SAS expander subsystem, where a race condition exists in the smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c. An attacker could abuse this flaw to corrupt memory and escalate privileges.
Package: kernel (Red Hat Enterprise Linux 5) - Will not fix
Package: kernel (Red Hat Enterprise Linux 6) - Will not fix
Package: kernel-alt (Red Hat Enterprise Linux 7) - Will not fix
Package: k
Debian
CVE-2018-20836: linux - An issue was discovered in the Linux kernel before 4.20. There is a race conditi...
vendor_debian·2018·CVSS 8.1
CVE-2018-20836 [HIGH] CVE-2018-20836: linux - An issue was discovered in the Linux kernel before 4.20. There is a race conditi...
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
GHSA
GHSA-hjqh-c7g9-6w2x: An issue was discovered in the Linux kernel before 4
ghsa_unreviewed·2022-05-24
CVE-2018-20836 [HIGH] CWE-362 GHSA-hjqh-c7g9-6w2x: An issue was discovered in the Linux kernel before 4
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
OSV
linux, linux-aws, linux-kvm, linux-raspi2 vulnerabilities
osv·2019-07-25·CVSS 8.1
CVE-2018-20836 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2 vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2 vulnerabilities
It was discovered that a race condition existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel. A local attacker could possibly
use this to cause a denial of service (system crash) or execute arbitrary
code. (CVE-2018-20836)
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)
It was discovered that the Bluetooth Human Interface Device Protocol (HIDP)
implementation in the Linux kernel did not properly verify strings were
NULL terminated in certain situations. A local attacker could use this to
expose sensitive information (kernel mem
OSV
CVE-2018-20836: An issue was discovered in the Linux kernel before 4
osv·2019-05-07·CVSS 8.1
CVE-2018-20836 [HIGH] CVE-2018-20836: An issue was discovered in the Linux kernel before 4
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00025.htmlhttp://www.securityfocus.com/bid/108196https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b90cd6f2b905905fb42671009dc0e27c310a16aehttps://github.com/torvalds/linux/commit/b90cd6f2b905905fb42671009dc0e27c310a16aehttps://lists.debian.org/debian-lts-announce/2019/08/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00017.htmlhttps://seclists.org/bugtraq/2019/Aug/13https://seclists.org/bugtraq/2019/Aug/18https://security.netapp.com/advisory/ntap-20190719-0003/https://support.f5.com/csp/article/K11225249https://usn.ubuntu.com/4076-1/https://www.debian.org/security/2019/dsa-4495https://www.debian.org/security/2019/dsa-4497http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00025.htmlhttp://www.securityfocus.com/bid/108196https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b90cd6f2b905905fb42671009dc0e27c310a16aehttps://github.com/torvalds/linux/commit/b90cd6f2b905905fb42671009dc0e27c310a16aehttps://lists.debian.org/debian-lts-announce/2019/08/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00017.htmlhttps://seclists.org/bugtraq/2019/Aug/13https://seclists.org/bugtraq/2019/Aug/18https://security.netapp.com/advisory/ntap-20190719-0003/https://support.f5.com/csp/article/K11225249https://usn.ubuntu.com/4076-1/https://www.debian.org/security/2019/dsa-4495https://www.debian.org/security/2019/dsa-4497
2019-05-07
Published