CVE-2018-7566
published 2018-03-30CVE-2018-7566: The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.50%
39.6th percentile
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.15.11-1 (bookworm) | linux 4.15.11-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.15.11-1 | 4.15.11-1 |
| linux | linux_kernel | >= 0 < 4.15.11-1 | 4.15.11-1 |
| linux | linux_kernel | >= 0 < 4.15.11-1 | 4.15.11-1 |
| linux | linux_kernel | >= 0 < 4.15.11-1 | 4.15.11-1 |
| linux | linux_kernel | >= 0 < 3.13.0-161.211 | 3.13.0-161.211 |
| linux | linux_kernel | >= 0 < 4.4.0-121.145 | 4.4.0-121.145 |
| oracle | communications_eagle_application_processor | — | — |
| oracle | communications_eagle_application_processor | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-23·CVSS 7.8
CVE-2015-8539 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Dmitry Vyukov discovered that the key management subsystem in the Linux
kernel did not properly restrict adding a key that already exists but is
negatively instantiated. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2015-8539)
It was discovered that a use-after-free vulnerability existed in the device
driver for XCeive xc2028/xc3028 tuners in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-7913)
Pengfei Ding (丁鹏飞), Chenfu Bao (包沉浮), and Lenx Wei (韦韬)
discovered a race condition in the generic SCSI driver (sg) of the Linux
kern
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-10-23·CVSS 7.8
CVE-2015-8539 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3798-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Dmitry Vyukov discovered that the key management subsystem in the Linux
kernel did not properly restrict adding a key that already exists but is
negatively instantiated. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2015-8539)
It was discovered that a use-after-free vulnerability existed in the device
driver for XCeive xc2028/xc3028 tuners in the Linux kernel. A local
attacker could use this to
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race condition existed in the
Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel when
handling ioctl()s. A local attacker could use this to cause a
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3631-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code.
Red Hat
kernel: race condition in snd_seq_write() may lead to UAF or OOB-access
vendor_redhat·2018-02-14·CVSS 7.8
CVE-2018-7566 [HIGH] CWE-362 kernel: race condition in snd_seq_write() may lead to UAF or OOB-access
kernel: race condition in snd_seq_write() may lead to UAF or OOB-access
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
ALSA sequencer core initializes the event pool on demand by invoking snd_seq_pool_init() when the first write happens and the pool is empty. A user can reset the pool size manually via ioctl concurrently, and this may lead to UAF or out-of-bound access.
Statement: This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5.
This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6, 7, its real-time kernel, Red Hat Enterprise MRG 2, Red Hat Enterprise Linux 7 for ARM 64 and Red Hat Enterprise Linux 7 fo
Debian
CVE-2018-7566: linux - The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_PO...
vendor_debian·2018·CVSS 7.8
CVE-2018-7566 [HIGH] CVE-2018-7566: linux - The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_PO...
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
Scope: local
bookworm: resolved (fixed in 4.15.11-1)
bullseye: resolved (fixed in 4.15.11-1)
forky: resolved (fixed in 4.15.11-1)
sid: resolved (fixed in 4.15.11-1)
trixie: resolved (fixed in 4.15.11-1)
GHSA
GHSA-qwh3-x82w-5462: The Linux kernel 4
ghsa_unreviewed·2022-05-13
CVE-2018-7566 [HIGH] CWE-119 GHSA-qwh3-x82w-5462: The Linux kernel 4
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
OSV
linux vulnerabilities
osv·2018-10-23·CVSS 7.8
CVE-2015-8539 [HIGH] linux vulnerabilities
linux vulnerabilities
Dmitry Vyukov discovered that the key management subsystem in the Linux
kernel did not properly restrict adding a key that already exists but is
negatively instantiated. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2015-8539)
It was discovered that a use-after-free vulnerability existed in the device
driver for XCeive xc2028/xc3028 tuners in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-7913)
Pengfei Ding (丁鹏飞), Chenfu Bao (包沉浮), and Lenx Wei (韦韬)
discovered a race condition in the generic SCSI driver (sg) of the Linux
kernel. A local attacker could use this to cause a denial of service
(system crash)
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race condition existed in the
Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel when
handling ioctl()s. A local attacker could use this to cause a denial of
service (system
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3631-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race conditi
OSV
CVE-2018-7566: The Linux kernel 4
osv·2018-03-30·CVSS 7.8
CVE-2018-7566 [HIGH] CVE-2018-7566: The Linux kernel 4
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7566 kernel: race condition in snd_seq_write() may lead to UAF or OOB-access [fedora-all]
bugzilla·2018-02-28·CVSS 7.8
CVE-2018-7566 [HIGH] CVE-2018-7566 kernel: race condition in snd_seq_write() may lead to UAF or OOB-access [fedora-all]
CVE-2018-7566 kernel: race condition in snd_seq_write() may lead to UAF or OOB-access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2018-7566 kernel: race condition in snd_seq_write() may lead to UAF or OOB-access
bugzilla·2018-02-28·CVSS 7.8
CVE-2018-7566 [HIGH] CVE-2018-7566 kernel: race condition in snd_seq_write() may lead to UAF or OOB-access
CVE-2018-7566 kernel: race condition in snd_seq_write() may lead to UAF or OOB-access
ALSA sequencer core initializes the event pool on demand by invoking snd_seq_pool_init() when the first write happens and the pool is empty. A user can reset the pool size manually via ioctl concurrently, and this may lead to UAF or out-of-bound access.
References:
http://mailman.alsa-project.org/pipermail/alsa-devel/2018-February/132026.html
https://marc.info/?l=alsa-devel&m=151859118611846&w=2
An upstream fix:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d15d662e89fc667b90cd294b0eb45694e33144da
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1550143]
---
This was fixed for Fedora with the 4.15.5 stable updates.
---
Statement
arXiv
Partially-Observable Security Games for Automating Attack-Defense Analysis
arxiv_fulltext·2022-11-02
Partially-Observable Security Games for Automating Attack-Defense Analysis
Partially-Observable Security Games for Automating Attack-Defense Analysis
Narges Khakpour
[email protected]
School of Computing, Newcastle University
Newcastle upon Tyne
UK
Department of Computer Science and Media Technology, Linnaeus University
Växjö
Sweden
David Parker
[email protected]
Department of Computer Science, Oxford University
Oxford
UK
## Abstract
Network systems often contain vulnerabilities that remain unfixed in a network for various reasons, such as the lack of a patch or knowledge to fix them. With the presence of such residual vulnerabilities, the network administrator should properly react to the malicious activities or proactively prevent them, by applying suitable countermeasures that minimize the likelihood of an attack by the attacker. In this
http://lists.opensuse.org/opensuse-security-announce/2018-03/msg00067.htmlhttp://mailman.alsa-project.org/pipermail/alsa-devel/2018-February/132026.htmlhttp://www.securityfocus.com/bid/103605https://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2390https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2018:2948https://access.redhat.com/errata/RHSA-2019:1483https://access.redhat.com/errata/RHSA-2019:1487https://bugzilla.redhat.com/show_bug.cgi?id=1550142https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d15d662e89fc667b90cd294b0eb45694e33144dahttps://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlhttps://usn.ubuntu.com/3631-1/https://usn.ubuntu.com/3631-2/https://usn.ubuntu.com/3798-1/https://usn.ubuntu.com/3798-2/https://www.debian.org/security/2018/dsa-4187https://www.debian.org/security/2018/dsa-4188https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-03/msg00067.htmlhttp://mailman.alsa-project.org/pipermail/alsa-devel/2018-February/132026.htmlhttp://www.securityfocus.com/bid/103605https://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2390https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2018:2948https://access.redhat.com/errata/RHSA-2019:1483https://access.redhat.com/errata/RHSA-2019:1487https://bugzilla.redhat.com/show_bug.cgi?id=1550142https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d15d662e89fc667b90cd294b0eb45694e33144dahttps://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/05/msg00000.htmlhttps://usn.ubuntu.com/3631-1/https://usn.ubuntu.com/3631-2/https://usn.ubuntu.com/3798-1/https://usn.ubuntu.com/3798-2/https://www.debian.org/security/2018/dsa-4187https://www.debian.org/security/2018/dsa-4188https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2018-03-30
Published