#VU14451 Information disclosure in Linux kernel - CVE-2018-7754

 

#VU14451 Information disclosure in Linux kernel - CVE-2018-7754

Published: August 17, 2018


Vulnerability identifier: #VU14451
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-7754
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Linux kernel
Software vendor:
Linux Foundation

Description

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to the aoedisk_debugfs_show function, as defined in the drivers/block/aoe/aoeblk.c source code file allows access to ffree:lines in a debugfs file. A local attacker can access the debugfs file to access sensitive address information, which could be used to conduct further attacks.


Remediation

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

External links