Buffer overflow in Linux kernel - CVE-2018-25020
Published: March 9, 2022
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the BPF subsystem in the Linux kernel in ernel/bpf/core.c and net/core/filter.c. The kernel mishandles situations with a long jump over an instruction sequence
where inner instructions require substantial expansions into multiple
BPF instructions. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code with elevated privileges.
Affected software
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Live Patching
SUSE Linux Enterprise Module for Live Patching
kgraft-patch-4_4_180-94_150-default
kgraft-patch-4_4_180-94_150-default-debuginfo
kgraft-patch-4_4_180-94_147-default-debuginfo
kgraft-patch-4_4_180-94_147-default
kgraft-patch-4_12_14-95_80-default
kgraft-patch-4_12_14-95_77-default
kgraft-patch-4_12_14-95_74-default
kgraft-patch-4_4_180-94_144-default
kgraft-patch-4_4_180-94_144-default-debuginfo
kgraft-patch-4_12_14-95_71-default
kgraft-patch-4_4_180-94_141-default
kgraft-patch-4_4_180-94_141-default-debuginfo
kgraft-patch-4_12_14-95_68-default
kernel-livepatch-4_12_14-150_66-default-debuginfo
kgraft-patch-4_4_180-94_138-default
kgraft-patch-4_4_180-94_138-default-debuginfo
kernel-livepatch-4_12_14-150_66-default
Pixel
How to mitigate CVE-2018-25020
kgraft-patch-4_4_180-94_150-default - update to 3-2.2
kgraft-patch-4_4_180-94_150-default-debuginfo - update to 3-2.2
kgraft-patch-4_4_180-94_147-default-debuginfo - update to 7-2.2
kgraft-patch-4_4_180-94_147-default - update to 7-2.2
kgraft-patch-4_12_14-95_80-default - update to 7-2.2
kgraft-patch-4_12_14-95_77-default - update to 9-2.2
kgraft-patch-4_12_14-95_74-default - update to 10-2.2
kgraft-patch-4_4_180-94_144-default - update to 10-2.2
kgraft-patch-4_4_180-94_144-default-debuginfo - update to 10-2.2
Pixel - update to 12L 2022-06-05
kgraft-patch-4_12_14-95_71-default - update to 13-2.2
kgraft-patch-4_4_180-94_141-default - update to 13-2.2
kgraft-patch-4_4_180-94_141-default-debuginfo - update to 13-2.2
kgraft-patch-4_12_14-95_68-default - update to 14-2.2
kernel-livepatch-4_12_14-150_66-default-debuginfo - update to 14-2.2
kgraft-patch-4_4_180-94_138-default - update to 14-2.2
kgraft-patch-4_4_180-94_138-default-debuginfo - update to 14-2.2
kernel-livepatch-4_12_14-150_66-default - update to 14-2.2
External References
Related Security Bulletins
- Privilege escalation in Linux kernel BPF subsystem
- Amazon Linux AMI update for kernel
- Multiple vulnerabilities in Google Pixel
- SUSE update for the Linux Kernel (Live Patch 41 for SLE 12 SP3)
- SUSE update for the Linux Kernel (Live Patch 22 for SLE 15)
- SUSE update for the Linux Kernel (Live Patch 18 for SLE 12 SP4)
- SUSE update for the Linux Kernel (Live Patch 20 for SLE 12 SP4)
- SUSE update for the Linux Kernel (Live Patch 37 for SLE 12 SP3)
- SUSE update for the Linux Kernel (Live Patch 39 for SLE 12 SP3)
- SUSE update for the Linux Kernel (Live Patch 40 for SLE 12 SP3)