CVE-2018-20856
published 2019-07-26CVE-2018-20856: An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.71%
49.8th percentile
An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.18.8-1 (bookworm) | linux 4.18.8-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 4.18.7 | 4.18.7 |
| linux | linux_kernel | >= 0 < 4.18.8-1 | 4.18.8-1 |
| linux | linux_kernel | >= 0 < 4.18.8-1 | 4.18.8-1 |
| linux | linux_kernel | >= 0 < 4.18.8-1 | 4.18.8-1 |
| linux | linux_kernel | >= 0 < 4.18.8-1 | 4.18.8-1 |
| linux | linux_kernel | >= 0 < 4.4.0-161.189 | 4.4.0-161.189 |
| linux | linux_kernel | >= 0 < 4.15.0-58.64 | 4.15.0-58.64 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-873h-38h4-56jx: An issue was discovered in the Linux kernel before 4
ghsa_unreviewed·2022-05-24
CVE-2018-20856 [HIGH] CWE-416 GHSA-873h-38h4-56jx: An issue was discovered in the Linux kernel before 4
An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-09-02·CVSS 7.8
CVE-2018-20856 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a use-after-free error existed in the block layer
subsystem of the Linux kernel when certain failure conditions occurred. A
local attacker could possibly use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2018-20856)
Amit Klein and Benny Pinkas discovered that the Linux kernel did not
sufficiently randomize IP ID values generated for connectionless networking
protocols. A remote attacker could use this to track particular Linux
devices. (CVE-2019-10638)
Praveen Pandey discovered that the Linux kernel did not properly validate
sent signals in some situations on PowerPC systems with transactional
memory disabled. A local attacker could use this to c
OSV
linux-aws vulnerabilities
osv·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] linux-aws vulnerabilities
linux-aws vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13096, CVE-2018-13097, CVE-2018-13098,
CVE-2018-1309
OSV
linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-08-13·CVSS 3.3
CVE-2018-13053 [LOW] linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate metadata. An attacker could
use this to construct a malicious f2fs image that, when moun
OSV
CVE-2018-20856: An issue was discovered in the Linux kernel before 4
osv·2019-07-26·CVSS 7.8
CVE-2018-20856 [HIGH] CVE-2018-20856: An issue was discovered in the Linux kernel before 4
An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled.
Android
CVE-2018-20856: Kernel
vendor_android·2020-01-01·CVSS 7.8
CVE-2018-20856 [HIGH] CVE-2018-20856: Kernel
Android Security Bulletin 2020-01-01
CVE: CVE-2018-20856
Severity: HIGH
Type: EoP
Component: Kernel
References: A-138921316
Upstream
kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-09-02·CVSS 7.8
CVE-2018-20856 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a use-after-free error existed in the block layer
subsystem of the Linux kernel when certain failure conditions occurred. A
local attacker could possibly use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2018-20856)
Amit Klein and Benny Pinkas discovered that the Linux kernel did not
sufficiently randomize IP ID values generated for connectionless networking
protocols. A remote attacker could use this to track particular Linux
devices. (CVE-2019-10638)
Praveen Pandey discovered that the Linux kernel did not properly validate
sent signals in some situations on PowerPC systems with transactional
memory disabled. A local at
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2019-09-02·CVSS 3.3
CVE-2018-13053 [LOW] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the Linux
kernel did not properly validate metadata. An attacker could use this to
construct a malicious f2fs image that, when mounted, could cause a denial
of serv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-08-13·CVSS 3.3
CVE-2018-13053 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
Wen Xu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate metadata. An attacker could
use this to construct a malicious f2fs image that, when mounted,
could cause a denial of service (s
Red Hat
kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c
vendor_redhat·2019-07-26·CVSS 7.8
CVE-2018-20856 [HIGH] CWE-119 kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c
kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c
An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled.
A flaw was found in the Linux kernel’s block driver implementation (blk_drain_queue() function) where a use-after-free condition could be triggered while draining the outstanding command queue in the systems block device subsystem. An attacker could use this flaw to crash the system or corrupt local memory, which may lead to privilege escalation.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt
Debian
CVE-2018-20856: linux - An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, ...
vendor_debian·2018·CVSS 7.8
CVE-2018-20856 [HIGH] CVE-2018-20856: linux - An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, ...
An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled.
Scope: local
bookworm: resolved (fixed in 4.18.8-1)
bullseye: resolved (fixed in 4.18.8-1)
forky: resolved (fixed in 4.18.8-1)
sid: resolved (fixed in 4.18.8-1)
trixie: resolved (fixed in 4.18.8-1)
No detection rules found.
No public exploits indexed.
arXiv
How Far Have We Gone in Vulnerability Detection Using Large Language Models
arxiv_fulltext·2023-12-22
How Far Have We Gone in Vulnerability Detection Using Large Language Models
## Abstract
As software becomes increasingly complex and prone to vulnerabilities, automated vulnerability detection is critically important, yet challenging. Given the significant successes of Large Language Models (LLMs) in various tasks, there is growing anticipation of their efficacy in vulnerability detection. However, a quantitative understanding of their potential in vulnerability detection is still missing.
To bridge this gap, we introduce a comprehensive vulnerability benchmark . This benchmark aggregates high-quality data from a wide range of CTF (Capture-the-Flag) (https://ctf-wiki.org/en/) challenges and real-world applications, with annotations for each vulnerable function detailing the vulnerability type and its root cause.
Through our experiments encompassing 16 LLMs and 6
Bugzilla
CVE-2018-20856 kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c [fedora-all]
bugzilla·2019-08-07·CVSS 7.8
CVE-2018-20856 [HIGH] CVE-2018-20856 kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c [fedora-all]
CVE-2018-20856 kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2018-20856 kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c
bugzilla·2019-08-07·CVSS 7.8
CVE-2018-20856 [HIGH] CVE-2018-20856 kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c
CVE-2018-20856 kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c
A flaw was found in the Linux kernels block driver implementation where a use-after-free condition could be triggered while draining the outstanding command queue in the systems block device subsystem.
A patient local attacker can use this flaw to corrupt memory, possibly crashing the system and possibly leading to privilege escalation.
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.7
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54648cf1ec2d7f4b6a71767799c45676a138ca24
https://github.com/torvalds/linux/commit/54648cf1ec2d7f4b6a71767799c45676a138ca24
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1738706]
---
This was
http://packetstormsecurity.com/files/154059/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttp://packetstormsecurity.com/files/154408/Kernel-Live-Patch-Security-Notice-LSN-0055-1.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttps://access.redhat.com/errata/RHSA-2019:3055https://access.redhat.com/errata/RHSA-2019:3076https://access.redhat.com/errata/RHSA-2019:3089https://access.redhat.com/errata/RHSA-2019:3217https://access.redhat.com/errata/RHSA-2020:0100https://access.redhat.com/errata/RHSA-2020:0103https://access.redhat.com/errata/RHSA-2020:0543https://access.redhat.com/errata/RHSA-2020:0664https://access.redhat.com/errata/RHSA-2020:0698https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.7https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54648cf1ec2d7f4b6a71767799c45676a138ca24https://github.com/torvalds/linux/commit/54648cf1ec2d7f4b6a71767799c45676a138ca24https://lists.debian.org/debian-lts-announce/2019/08/msg00017.htmlhttps://seclists.org/bugtraq/2019/Aug/18https://seclists.org/bugtraq/2019/Aug/26https://security.netapp.com/advisory/ntap-20190905-0002/https://support.f5.com/csp/article/K14673240?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4094-1/https://usn.ubuntu.com/4116-1/https://usn.ubuntu.com/4118-1/https://www.debian.org/security/2019/dsa-4497http://packetstormsecurity.com/files/154059/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttp://packetstormsecurity.com/files/154408/Kernel-Live-Patch-Security-Notice-LSN-0055-1.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttps://access.redhat.com/errata/RHSA-2019:3055https://access.redhat.com/errata/RHSA-2019:3076https://access.redhat.com/errata/RHSA-2019:3089https://access.redhat.com/errata/RHSA-2019:3217https://access.redhat.com/errata/RHSA-2020:0100https://access.redhat.com/errata/RHSA-2020:0103https://access.redhat.com/errata/RHSA-2020:0543https://access.redhat.com/errata/RHSA-2020:0664https://access.redhat.com/errata/RHSA-2020:0698https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.7https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54648cf1ec2d7f4b6a71767799c45676a138ca24https://github.com/torvalds/linux/commit/54648cf1ec2d7f4b6a71767799c45676a138ca24https://lists.debian.org/debian-lts-announce/2019/08/msg00017.htmlhttps://seclists.org/bugtraq/2019/Aug/18https://seclists.org/bugtraq/2019/Aug/26https://security.netapp.com/advisory/ntap-20190905-0002/https://support.f5.com/csp/article/K14673240?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4094-1/https://usn.ubuntu.com/4116-1/https://usn.ubuntu.com/4118-1/https://www.debian.org/security/2019/dsa-4497
2019-07-26
Published