CVE-2018-5953
published 2018-08-07CVE-2018-5953: The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.40%
32.9th percentile
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 4.15.4-1 (bookworm) | linux 4.15.4-1 (bookworm) |
| gnu | wget | >= 0 < 1.15-1ubuntu1.14.04.5 | 1.15-1ubuntu1.14.04.5 |
| gnu | wget | >= 0 < 1.17.1-1ubuntu1.5 | 1.17.1-1ubuntu1.5 |
| gnu | wget | >= 0 < 1.19.4-1ubuntu2.2 | 1.19.4-1ubuntu2.2 |
| linux | linux_kernel | <= 4.14.14 | — |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.4 | 2:7.4.1689-3ubuntu1.4 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.3 | 2:8.0.1453-1ubuntu1.3 |
| vim | vim | >= 0 < 2:7.4.052-1ubuntu3.1+esm1 | 2:7.4.052-1ubuntu3.1+esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Information Exposure through dmesg data from a "software IO TLB" printk call
vendor_redhat·2018-08-07·CVSS 5.5
CVE-2018-5953 [MEDIUM] CWE-200 kernel: Information Exposure through dmesg data from a "software IO TLB" printk call
kernel: Information Exposure through dmesg data from a "software IO TLB" printk call
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
A flaw was found in the Linux kernel where the swiotlb_print_info() function in lib/swiotlb.c allows local users to obtain some kernel address information by reading the kernel log (dmesg). This address is not useful to commit a further attack.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel
Debian
CVE-2018-5953: linux - The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.1...
vendor_debian·2018·CVSS 5.5
CVE-2018-5953 [MEDIUM] CVE-2018-5953: linux - The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.1...
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
Scope: local
bookworm: resolved (fixed in 4.15.4-1)
bullseye: resolved (fixed in 4.15.4-1)
forky: resolved (fixed in 4.15.4-1)
sid: resolved (fixed in 4.15.4-1)
trixie: resolved (fixed in 4.15.4-1)
GHSA
GHSA-fcj2-wp76-hhxr: The swiotlb_print_info function in lib/swiotlb
ghsa_unreviewed·2022-05-13
CVE-2018-5953 [MEDIUM] CWE-200 GHSA-fcj2-wp76-hhxr: The swiotlb_print_info function in lib/swiotlb
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
OSV
vim vulnerabilities
osv·2020-03-23·CVSS 7.8
CVE-2017-11109 vim vulnerabilities
vim vulnerabilities
It was discovered that Vim incorrectly handled certain sources.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM and
Ubuntu 16.04 LTS (CVE-2017-11109)
It was discovered that Vim incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
(CVE-2017-5953)
It was discovered that Vim incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.06 LTS. (CVE-2018-20786)
It was discovered that Vim incorrectly handled certain inputs. An attacker
could possibly use this issue to cause a denial of service or
OSV
wget vulnerabilities
osv·2019-04-08·CVSS 7.8
CVE-2018-20483 wget vulnerabilities
wget vulnerabilities
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20483)
Kusano Kazuhiko discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-5953)
OSV
CVE-2018-5953: The swiotlb_print_info function in lib/swiotlb
osv·2018-08-07·CVSS 5.5
CVE-2018-5953 [MEDIUM] CVE-2018-5953: The swiotlb_print_info function in lib/swiotlb
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/105045https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7d63fb3af87aa67aa7d24466e792f9d7c57d8e79https://github.com/johnsonwangqize/cve-linux/blob/master/%20CVE-2018-5953.mdhttps://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttp://www.securityfocus.com/bid/105045https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7d63fb3af87aa67aa7d24466e792f9d7c57d8e79https://github.com/johnsonwangqize/cve-linux/blob/master/%20CVE-2018-5953.mdhttps://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.html
2018-08-07
Published