CVE-2018-10675

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.

References

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=73223e4e2e3867ebf033a5a8eb2e5df0158ccc99

http://www.securityfocus.com/bid/104093

https://access.redhat.com/errata/RHSA-2018:2164

https://access.redhat.com/errata/RHSA-2018:2384

https://access.redhat.com/errata/RHSA-2018:2395

https://access.redhat.com/errata/RHSA-2018:2785

https://access.redhat.com/errata/RHSA-2018:2791

https://access.redhat.com/errata/RHSA-2018:2924

https://access.redhat.com/errata/RHSA-2018:2925

https://access.redhat.com/errata/RHSA-2018:2933

https://access.redhat.com/errata/RHSA-2018:3540

https://access.redhat.com/errata/RHSA-2018:3586

https://access.redhat.com/errata/RHSA-2018:3590

https://github.com/torvalds/linux/commit/73223e4e2e3867ebf033a5a8eb2e5df0158ccc99

https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0

https://usn.ubuntu.com/3754-1/

https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.9

https://www.oracle.com/security-alerts/cpujul2020.html

Details

Source: MITRE

Published: 2018-05-02

Updated: 2020-07-15

Type: CWE-416

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Tenable Plugins

View all (39 total)

IDNameProductFamilySeverity
131845EulerOS 2.0 SP2 : kernel (EulerOS-SA-2019-2353)NessusHuawei Local Security Checks
critical
130736EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2274)NessusHuawei Local Security Checks
critical
127408NewStart CGSL MAIN 4.05 : kernel Multiple Vulnerabilities (NS-SA-2019-0143)NessusNewStart CGSL Local Security Checks
critical
127192NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2019-0028)NessusNewStart CGSL Local Security Checks
high
127185NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0025)NessusNewStart CGSL Local Security Checks
high
124830EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1507)NessusHuawei Local Security Checks
high
124795EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1471)NessusHuawei Local Security Checks
high
121067Juniper Junos Space < 18.3R1 Multiple Vulnerabilities (JSA10917)NessusJunos Local Security Checks
high
119112RHEL 6 : MRG (RHSA-2018:3586)NessusRed Hat Local Security Checks
high
118947RHEL 7 : kernel (RHSA-2018:3590)NessusRed Hat Local Security Checks
high
118946RHEL 7 : kernel (RHSA-2018:3540)NessusRed Hat Local Security Checks
high
118165RHEL 6 : kernel (RHSA-2018:2933)NessusRed Hat Local Security Checks
high
118164RHEL 6 : kernel (RHSA-2018:2925)NessusRed Hat Local Security Checks
high
118163RHEL 6 : kernel (RHSA-2018:2924)NessusRed Hat Local Security Checks
high
117783RHEL 6 : kernel (RHSA-2018:2791)NessusRed Hat Local Security Checks
high
117781RHEL 7 : kernel (RHSA-2018:2785)NessusRed Hat Local Security Checks
high
117513Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2018-4214) (Foreshadow)NessusOracle Linux Local Security Checks
high
117446Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4211)NessusOracle Linux Local Security Checks
high
112206Virtuozzo 7 : OVMF / crit / criu / criu-devel / ksm-vz / etc (VZA-2018-063)NessusVirtuozzo Local Security Checks
high
112113Ubuntu 14.04 LTS : Linux kernel vulnerabilities (USN-3754-1)NessusUbuntu Local Security Checks
critical
111778Scientific Linux Security Update : kernel on SL7.x x86_64 (20180814) (Foreshadow)NessusScientific Linux Local Security Checks
high
111736RHEL 7 : kernel-rt (RHSA-2018:2395) (Foreshadow)NessusRed Hat Local Security Checks
high
111727RHEL 7 : kernel (RHSA-2018:2384) (Foreshadow)NessusRed Hat Local Security Checks
high
111723Oracle Linux 7 : kernel (ELSA-2018-2384) (Foreshadow)NessusOracle Linux Local Security Checks
high
111703CentOS 7 : kernel (CESA-2018:2384) (Foreshadow)NessusCentOS Local Security Checks
high
111077CentOS 6 : kernel (CESA-2018:2164) (Spectre)NessusCentOS Local Security Checks
high
111002Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20180710) (Spectre)NessusScientific Linux Local Security Checks
high
111001RHEL 6 : kernel (RHSA-2018:2164) (Spectre)NessusRed Hat Local Security Checks
high
110996Oracle Linux 6 : kernel (ELSA-2018-2164) (Spectre)NessusOracle Linux Local Security Checks
high
110694Virtuozzo 6 : parallels-server-bm-release / vzkernel / etc (VZA-2018-041)NessusVirtuozzo Local Security Checks
high
110197Amazon Linux AMI : kernel (ALAS-2018-1023)NessusAmazon Linux Local Security Checks
high
110136EulerOS 2.0 SP1 : kernel (EulerOS-SA-2018-1132)NessusHuawei Local Security Checks
medium
110072OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0223) (Spectre)NessusOracleVM Local Security Checks
high
110071Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4114) (Spectre)NessusOracle Linux Local Security Checks
high
110041SUSE SLES11 Security Update : kernel (SUSE-SU-2018:1376-1) (Spectre)NessusSuSE Local Security Checks
high
110040SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1375-1) (Spectre)NessusSuSE Local Security Checks
high
110039SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1374-1) (Spectre)NessusSuSE Local Security Checks
high
110035SUSE SLES11 Security Update : kernel (SUSE-SU-2018:1368-1) (Spectre)NessusSuSE Local Security Checks
high
109177Amazon Linux 2 : kernel (ALAS-2018-994)NessusAmazon Linux Local Security Checks
high