CVE-2018-20976
published 2019-08-19CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
PriorityP340high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.61%
45.6th percentile
An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.18.6-1 (bookworm) | linux 4.18.6-1 (bookworm) |
| linux | linux_kernel | < 4.18 | 4.18 |
| linux | linux_kernel | >= 0 < 4.18.6-1 | 4.18.6-1 |
| linux | linux_kernel | >= 0 < 4.18.6-1 | 4.18.6-1 |
| linux | linux_kernel | >= 0 < 4.18.6-1 | 4.18.6-1 |
| linux | linux_kernel | >= 0 < 4.18.6-1 | 4.18.6-1 |
| linux | linux_kernel | >= 0 < 4.4.0-165.193 | 4.4.0-165.193 |
| linux | linux_kernel | >= 0 < 4.15.0-65.74 | 4.15.0-65.74 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2px5-xhf9-x464: An issue was discovered in fs/xfs/xfs_super
ghsa_unreviewed·2022-05-24
CVE-2018-20976 [HIGH] CWE-416 GHSA-2px5-xhf9-x464: An issue was discovered in fs/xfs/xfs_super
An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-10-01·CVSS 7.8
CVE-2018-20976 [HIGH] linux, linux-aws, linux-aws-hwe, linux-azure, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the XFS file system in the Linux kernel did not
properly handle mount failures in some situations. A local attacker could
possibly use this to cause a denial of service (system crash) or execute
arbitrary code. (CVE-2018-20976)
Benjamin Moody discovered that the XFS file system in the Linux kernel did
not properly handle an error condition when out of disk quota. A local
attacker could possibly use this to cause a denial of service.
(CVE-2019-15538)
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-10-01·CVSS 7.8
CVE-2016-10905 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a race condition existed in the GFS2 file system in
the Linux kernel. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2016-10905)
It was discovered that the IPv6 implementation in the Linux kernel did not
properly validate socket options in some situations. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-18509)
It was discovered that the USB gadget Midi driver in the Linux kernel
contained a double-free vulnerability when handling certain error
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-20961)
It was discovered that th
OSV
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super
osv·2019-08-19·CVSS 7.8
CVE-2018-20976 [HIGH] CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super
An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-10-01·CVSS 7.8
CVE-2016-10905 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the GFS2 file system in
the Linux kernel. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2016-10905)
It was discovered that the IPv6 implementation in the Linux kernel did not
properly validate socket options in some situations. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-18509)
It was discovered that the USB gadget Midi driver in the Linux kernel
contained a double-free vulnerability when handling certain error
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-20961)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-10-01·CVSS 7.8
CVE-2018-20976 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the XFS file system in the Linux kernel did not
properly handle mount failures in some situations. A local attacker could
possibly use this to cause a denial of service (system crash) or execute
arbitrary code. (CVE-2018-20976)
Benjamin Moody discovered that the XFS file system in the Linux kernel did
not properly handle an error condition when out of disk quota. A local
attacker could possibly use this to cause a denial of service.
(CVE-2019-15538)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, whi
Red Hat
kernel: use-after-free in fs/xfs/xfs_super.c
vendor_redhat·2018-05-15·CVSS 7.8
CVE-2018-20976 [HIGH] CWE-416 kernel: use-after-free in fs/xfs/xfs_super.c
kernel: use-after-free in fs/xfs/xfs_super.c
An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
A flaw was found in the Linux kernel's implementation of the XFS filesystem. A key data structure (sb->s_fs_info) may not be de-allocated when the system is under memory pressure. This same data structure is then used at a later time during filesystem operations. This could allow a local attacker who is able to groom memory to place an attacker-controlled data structure in this location and create a use-after-free situation which can result in memory corruption or privilege escalation.
Statement: Red Hat Enterprise Linux 7.6.z had fixed this flaw mid release without it being recognised as a CVE. Prior r
Debian
CVE-2018-20976: linux - An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A...
vendor_debian·2018·CVSS 7.8
CVE-2018-20976 [HIGH] CVE-2018-20976: linux - An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A...
An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
Scope: local
bookworm: resolved (fixed in 4.18.6-1)
bullseye: resolved (fixed in 4.18.6-1)
forky: resolved (fixed in 4.18.6-1)
sid: resolved (fixed in 4.18.6-1)
trixie: resolved (fixed in 4.18.6-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttp://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttps://access.redhat.com/errata/RHSA-2020:0178https://access.redhat.com/errata/RHSA-2020:0543https://access.redhat.com/errata/RHSA-2020:0592https://access.redhat.com/errata/RHSA-2020:0609https://access.redhat.com/errata/RHSA-2020:0661https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c9fbd7bbc23dbdd73364be4d045e5d3612cf6e82https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlhttps://seclists.org/bugtraq/2019/Nov/11https://security.netapp.com/advisory/ntap-20190905-0002/https://support.f5.com/csp/article/K10269585?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4144-1/https://usn.ubuntu.com/4145-1/http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.htmlhttp://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlhttp://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlhttps://access.redhat.com/errata/RHSA-2020:0178https://access.redhat.com/errata/RHSA-2020:0543https://access.redhat.com/errata/RHSA-2020:0592https://access.redhat.com/errata/RHSA-2020:0609https://access.redhat.com/errata/RHSA-2020:0661https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c9fbd7bbc23dbdd73364be4d045e5d3612cf6e82https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlhttps://seclists.org/bugtraq/2019/Nov/11https://security.netapp.com/advisory/ntap-20190905-0002/https://support.f5.com/csp/article/K10269585?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4144-1/https://usn.ubuntu.com/4145-1/
2019-08-19
Published