CVE-2018-5995
published 2018-08-07CVE-2018-5995: The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.41%
33.6th percentile
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.15.4-1 (bookworm) | linux 4.15.4-1 (bookworm) |
| linux | linux_kernel | <= 4.14.14 | — |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.15.4-1 | 4.15.4-1 |
| linux | linux_kernel | >= 0 < 4.4.0-222.255 | 4.4.0-222.255 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 7.8
CVE-2020-25673 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that the aufs file system in the Linux kernel did not
properly restrict mount namespaces, when mounted with the non-default
allow_userns option set. A local attacker could use this to gain
administrative privileges. (CVE-2016-2853)
It was discovered that the aufs file system in the Linux kernel did not
properly maintain POSIX ACL xattr data, when mounted with the non-default
allow_userns option. A local attacker could possibly us
Red Hat
kernel: Information Exposure through dmesg data from a "pages/cpu" printk call
vendor_redhat·2018-08-07·CVSS 5.5
CVE-2018-5995 [MEDIUM] CWE-200 kernel: Information Exposure through dmesg data from a "pages/cpu" printk call
kernel: Information Exposure through dmesg data from a "pages/cpu" printk call
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.
An information-exposure flaw was found in the Linux kernel where the pcpu_embed_first_chunk() function in mm/percpu.c allows local users to obtain kernel-object address information by reading the kernel log (dmesg). However, this address is not static and cannot be used to commit a further attack.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterpr
Debian
CVE-2018-5995: linux - The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4...
vendor_debian·2018·CVSS 5.5
CVE-2018-5995 [MEDIUM] CVE-2018-5995: linux - The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4...
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.
Scope: local
bookworm: resolved (fixed in 4.15.4-1)
bullseye: resolved (fixed in 4.15.4-1)
forky: resolved (fixed in 4.15.4-1)
sid: resolved (fixed in 4.15.4-1)
trixie: resolved (fixed in 4.15.4-1)
GHSA
GHSA-8cxx-w4mr-45j5: The pcpu_embed_first_chunk function in mm/percpu
ghsa_unreviewed·2022-05-14
CVE-2018-5995 [MEDIUM] CWE-200 GHSA-8cxx-w4mr-45j5: The pcpu_embed_first_chunk function in mm/percpu
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2022-03-22·CVSS 7.8
CVE-2022-0492 [HIGH] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that the aufs file system in the Linux kernel did not
properly restrict mount namespaces, when mounted with the non-default
allow_userns option set. A local attacker could use this to gain
administrative privileges. (CVE-2016-2853)
It was discovered that the aufs file system in the Linux kernel did not
properly maintain POSIX ACL xattr data, when mounted with the non-default
allow_userns option. A local attacker could possibly use this to gain
elevated privileges. (CVE
OSV
CVE-2018-5995: The pcpu_embed_first_chunk function in mm/percpu
osv·2018-08-07·CVSS 5.5
CVE-2018-5995 [MEDIUM] CVE-2018-5995: The pcpu_embed_first_chunk function in mm/percpu
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/105049https://github.com/johnsonwangqize/cve-linux/blob/master/CVE-2018-5995.mdhttps://lists.debian.org/debian-lts-announce/2019/05/msg00041.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00042.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00017.htmlhttps://seclists.org/bugtraq/2019/Aug/18https://www.debian.org/security/2019/dsa-4497http://www.securityfocus.com/bid/105049https://github.com/johnsonwangqize/cve-linux/blob/master/CVE-2018-5995.mdhttps://lists.debian.org/debian-lts-announce/2019/05/msg00041.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00042.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00017.htmlhttps://seclists.org/bugtraq/2019/Aug/18https://www.debian.org/security/2019/dsa-4497
2018-08-07
Published