Buffer overflow in Block IO Tracing - CVE-2018-10689
Published: November 23, 2019
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the dev_map_read() function in btt/devmap.c in blktrace. A local user can create a specially crafted file, pass it to he application that is using the vulnerable component (e.g. btt program), trigger memory corruption and execute arbitrary code with elevated privileges.
Affected software
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Fedora
blktrace
Session Smart Router
How to mitigate CVE-2018-10689
Session Smart Router - addressed in versions 5.4.7, 5.5.3
External References
- http://git.kernel.dk/?p=blktrace.git;a=log;h=d61ff409cb4dda31386373d706ea0cfb1aaac5b7
- https://access.redhat.com/errata/RHSA-2019:2162
- https://git.kernel.org/pub/scm/linux/kernel/git/axboe/blktrace.git/commit/?id=d61ff409cb4dda31386373d706ea0cfb1aaac5b7
- https://www.spinics.net/lists/linux-btrace/msg00847.html
Related Security Bulletins
- Buffer overflow in blktrace
- Amazon Linux AMI update for blktrace
- Red Hat update for blktrace
- OpenSUSE Linux update for blktrace
- Gentoo update for blktrace
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Fedora 27 update for blktrace
- Fedora 26 update for blktrace
- Fedora 28 update for blktrace