Heap-based buffer overflow in Linux kernel - CVE-2018-10840

 

Heap-based buffer overflow in Linux kernel - CVE-2018-10840

Published: June 6, 2018


Vulnerability identifier: #VU13199
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10840
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists due to heap-based buffer overflow in fs/ext4/xattr.c:ext4_xattr_set_entry(). A local attacker can supply specially crafted ext4 image, trigger memory corruption and cause the system to crash.

Affected software

Linux kernel
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Fedora

kernel-alt (Red Hat package)
kernel

How to mitigate CVE-2018-10840

Update to version 4.16.12.

kernel-alt (Red Hat package) - update to 4.14.0-115.5.1.el7a
kernel - addressed in versions 4.16.12-200.fc27, 4.16.12-300.fc28

External References

Related Security Bulletins