Oval Definition:oval:com.ubuntu.xenial:def:2018114120000000
Revision Date:2018-05-24Version:1
Title:CVE-2018-11412 on Ubuntu 16.04 LTS (xenial) - medium.
Description:In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode. Jann Horn discovered that the ext4 filesystem implementation in the Linux kernel did not properly keep xattr information consistent in some situations. An attacker could use this to construct a malicious ext4 image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-11412
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • linux-azure package in xenial was vulnerable but has been fixed (note: '4.15.0-1022.22~16.04.1').
  • OR linux-flo: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'abandoned').
  • OR linux-gcp package in xenial was vulnerable but has been fixed (note: '4.15.0-1018.19~16.04.2').
  • OR linux-gke: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'was needs-triage now end-of-life').
  • OR linux-goldfish: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'was needs-triage now end-of-life').
  • OR linux-hwe package in xenial was vulnerable but has been fixed (note: '4.15.0-33.36~16.04.1').
  • OR linux-mako: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'abandoned').
  • OR linux-meta-azure package in xenial was vulnerable but has been fixed (note: '4.15.0-1022.22~16.04.1').
  • OR linux-meta-gcp package in xenial was vulnerable but has been fixed (note: '4.15.0-1018.19~16.04.2').
  • OR linux-meta-hwe package in xenial was vulnerable but has been fixed (note: '4.15.0-33.36~16.04.1').
  • OR linux-oem: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'was needed now end-of-life').
  • OR linux-signed-azure package in xenial was vulnerable but has been fixed (note: '4.15.0-1022.22~16.04.1').
  • OR linux-signed-gcp package in xenial was vulnerable but has been fixed (note: '4.15.0-1018.19~16.04.2').
  • OR linux-signed-hwe package in xenial was vulnerable but has been fixed (note: '4.15.0-33.36~16.04.1').
  • BACK