CVE-2018-7995Race Condition in Linux

CWE-362Race Condition14 documents7 sources
Severity
4.7MEDIUMNVD
OSV5.5
EPSS
0.1%
top 81.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 9
Latest updateMay 14

Description

Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (panic) by leveraging root access to write to the check_interval file in a /sys/devices/system/machinecheck/machinecheck directory. NOTE: a third party has indicated that this report is not security relevant

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages4 packages

Debianlinux/linux_kernel< 4.15.11-1+3
Ubuntulinux/linux_kernel< 4.4.0-127.153
NVDlinux/linux_kernel4.15.7
debiandebian/linux< linux 4.15.11-1 (bookworm)

Also affects: Debian Linux 7.0, Ubuntu Linux 14.04, 16.04

Patches

🔴Vulnerability Details

5
GHSA
GHSA-84fm-f9m3-wc94: ** DISPUTED ** Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce2022-05-14
OSV
linux, linux-aws, linux-kvm, vulnerabilities2018-05-22
OSV
linux-lts-xenial, linux-aws vulnerabilities2018-05-22
OSV
linux-raspi2, linux-snapdragon vulnerabilities2018-05-22
OSV
CVE-2018-7995: Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce2018-03-09

📋Vendor Advisories

5
Ubuntu
Linux kernel vulnerabilities2018-05-22
Ubuntu
Linux kernel (Raspberry Pi 2, Snapdragon) vulnerabilities2018-05-22
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2018-05-22
Red Hat
kernel: Race condition in the store_int_with_restart() function in cpu/mcheck/mce.c2018-03-09
Debian
CVE-2018-7995: linux - Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/m...2018

💬Community

3
Bugzilla
CVE-2018-7995 kernel: Race condition in the store_int_with_restart() function in cpu/mcheck/mce.c2018-03-09
Bugzilla
CVE-2018-7995 kernel: Race condition in the store_int_with_restart() function in cpu/mcheck/mce.c [fedora-all]2018-03-09
Bugzilla
CVE-2018-7995 kernel: Race condition in the store_int_with_restart() function in cpu/mcheck/mce.c [fedora-all]2018-03-09