Information disclosure in Linux kernel - CVE-2018-10940

 

Information disclosure in Linux kernel - CVE-2018-10940

Published: June 15, 2018 / Updated: May 30, 2020


Vulnerability identifier: #VU13363
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10940
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists in the cdrom_ioctl_media_changed function due to incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED IOCTL. A local attacker can execute a file or program that submits malicious input to the targeted system, trigger memory corruption and access sensitive kernel information, which could be used to conduct further attacks.


Affected software

Linux kernel
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Opensuse
kernel-alt (Red Hat package)

How to mitigate CVE-2018-10940

Update to version 4.16.6.

Linux kernel - addressed in versions 4.2, 4.4.164, 4.9.138, 4.14.82, 4.16.6, 4.18.20, 4.19.3
kernel-alt (Red Hat package) - update to 4.14.0-115.el7a

External References

Related Security Bulletins