Information disclosure in Linux kernel - CVE-2018-18710
Published: October 30, 2018 / Updated: November 1, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the cdrom_ioctl_select_disc function, as defined in the drivers/cdrom/cdrom.c source code file due to boundary error when processing of user-supplied input. A local attacker can access the system, execute an application that submits malicious input to read arbitrary kernel memory on the system, which could be used to conduct additional attacks.
Affected software
Amazon Linux AMI
Opensuse
Fedora
kernel
kernel-headers
kernel-tools
How to mitigate CVE-2018-18710
kernel-headers - addressed in versions 4.18.19-100.fc27, 4.19.2-200.fc28, 4.19.2-300.fc29
kernel-tools - addressed in versions 4.18.19-100.fc27, 4.19.2-200.fc28, 4.19.2-300.fc29
External References
Related Security Bulletins
- Information disclosure in Linux kernel
- OpenSUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for the Linux Kernel
- Amazon Linux AMI update for kernel
- Fedora 29 update for kernel, kernel-headers, kernel-tools
- Fedora 28 update for kernel, kernel-headers, kernel-tools
- Fedora 27 update for kernel, kernel-headers, kernel-tools