Vulnerability Name: | CVE-2018-12633 (CCN-145216) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2018-05-14 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2018-05-14 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2018-08-21 | ||||||||||||||||||||||||||||||||||||||||
Summary: | An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H) 5.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
7.9 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.3 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:N/A:C)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-362 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-12633 Source: MISC Type: Patch, Vendor Advisory http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=bd23a7269834dc7c1f93e83535d16ebc44b75eba Source: MISC Type: Issue Tracking, Vendor Advisory https://bugzilla.kernel.org/show_bug.cgi?id=200131 Source: XF Type: UNKNOWN linux-kernel-cve201812633-dos(145216) Source: CCN Type: Linux Kernel GIT Repository virt: vbox: Only copy_from_user the request-header once Source: MISC Type: Patch, Third Party Advisory https://github.com/torvalds/linux/commit/bd23a7269834dc7c1f93e83535d16ebc44b75eba Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-12633 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |