Double Free in elfutils - CVE-2018-16402

 

Double Free in elfutils - CVE-2018-16402

Published: September 3, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36733
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16402
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.


Affected software

elfutils
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Opensuse
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
Fedora
elfutils (Red Hat package)
elfutils
libelf-devel
libelf1
libelf1-debuginfo
libasm1-32bit
libasm1-32bit-debuginfo
libdw1-32bit
libdw1-32bit-debuginfo
libebl-plugins-32bit
libebl-plugins-32bit-debuginfo
libelf-devel-32bit
libelf1-32bit
libelf1-32bit-debuginfo
elfutils-lang
libebl-plugins
libebl-plugins-debuginfo
libebl-devel
elfutils-debuginfo
libdw1-debuginfo
elfutils-debugsource
libasm-devel
libasm1
libdw1
libdw-devel
libasm1-debuginfo
dwarves-debuginfo
dwarves-debugsource
libdwarves1-32bit-debuginfo
libdwarves1-32bit
libdwarves-devel-32bit
libdwarves-devel
libdwarves1
libdwarves1-debuginfo
dwarves

How to mitigate CVE-2018-16402

Install update from vendor's website.

elfutils (Red Hat package) - addressed in versions 0.172-4.el7_6, 0.176-2.el7
elfutils - addressed in versions 0.174-1.fc28, 0.174-1.fc29
libelf-devel - update to 0.177-150300.11.3.1
libelf1 - update to 0.177-150300.11.3.1
libelf1-debuginfo - update to 0.177-150300.11.3.1
libasm1-32bit - update to 0.177-150300.11.3.1
libasm1-32bit-debuginfo - update to 0.177-150300.11.3.1
libdw1-32bit - update to 0.177-150300.11.3.1
libdw1-32bit-debuginfo - update to 0.177-150300.11.3.1
libebl-plugins-32bit - update to 0.177-150300.11.3.1
libebl-plugins-32bit-debuginfo - update to 0.177-150300.11.3.1
libelf-devel-32bit - update to 0.177-150300.11.3.1
libelf1-32bit - update to 0.177-150300.11.3.1
libelf1-32bit-debuginfo - update to 0.177-150300.11.3.1
elfutils-lang - update to 0.177-150300.11.3.1
libebl-plugins - update to 0.177-150300.11.3.1
libebl-plugins-debuginfo - update to 0.177-150300.11.3.1
libebl-devel - update to 0.177-150300.11.3.1
elfutils - update to 0.177-150300.11.3.1
elfutils-debuginfo - update to 0.177-150300.11.3.1
libdw1-debuginfo - update to 0.177-150300.11.3.1
elfutils-debugsource - update to 0.177-150300.11.3.1
libasm-devel - update to 0.177-150300.11.3.1
libasm1 - update to 0.177-150300.11.3.1
libdw1 - update to 0.177-150300.11.3.1
libdw-devel - update to 0.177-150300.11.3.1
libasm1-debuginfo - update to 0.177-150300.11.3.1
dwarves-debuginfo - update to 1.22-150300.7.3.1
dwarves-debugsource - update to 1.22-150300.7.3.1
libdwarves1-32bit-debuginfo - update to 1.22-150300.7.3.1
libdwarves1-32bit - update to 1.22-150300.7.3.1
libdwarves-devel-32bit - update to 1.22-150300.7.3.1
libdwarves-devel - update to 1.22-150300.7.3.1
libdwarves1 - update to 1.22-150300.7.3.1
libdwarves1-debuginfo - update to 1.22-150300.7.3.1
dwarves - update to 1.22-150300.7.3.1

External References

Related Security Bulletins