A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mounting and operating a crafted ext4 image.
http://patchwork.ozlabs.org/patch/929239/
http://www.securityfocus.com/bid/104904
http://www.securityfocus.com/bid/106503
https://access.redhat.com/errata/RHSA-2019:0525
https://bugzilla.kernel.org/show_bug.cgi?id=199403
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10876
https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html
https://usn.ubuntu.com/3753-1/
https://usn.ubuntu.com/3753-2/
https://usn.ubuntu.com/3871-1/
https://usn.ubuntu.com/3871-3/
Source: MITRE
Published: 2018-07-26
Updated: 2019-04-01
Type: CWE-416
Base Score: 4.9
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C
Impact Score: 6.9
Exploitability Score: 3.9
Severity: MEDIUM
Base Score: 5.5
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 1.8
Severity: MEDIUM
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
141697 | EulerOS Virtualization 3.0.2.2 : kernel (EulerOS-SA-2020-2222) | Nessus | Huawei Local Security Checks | high |
125515 | EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-1588) | Nessus | Huawei Local Security Checks | medium |
124398 | EulerOS 2.0 SP2 : kernel (EulerOS-SA-2019-1302) | Nessus | Huawei Local Security Checks | high |
123269 | openSUSE Security Update : the Linux Kernel (openSUSE-2019-618) (Foreshadow) | Nessus | SuSE Local Security Checks | medium |
122837 | OracleVM 3.4 : Unbreakable / etc (OVMSA-2019-0009) | Nessus | OracleVM Local Security Checks | high |
122807 | RHEL 7 : kernel-alt (RHSA-2019:0525) | Nessus | Red Hat Local Security Checks | medium |
122805 | Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2019-4577) | Nessus | Oracle Linux Local Security Checks | high |
122804 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2019-4576) | Nessus | Oracle Linux Local Security Checks | high |
122803 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2019-4575) | Nessus | Oracle Linux Local Security Checks | high |
122052 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS : linux-azure vulnerabilities (USN-3871-5) | Nessus | Ubuntu Local Security Checks | high |
121594 | Ubuntu 16.04 LTS : linux-hwe, linux-aws-hwe, linux-gcp vulnerabilities (USN-3871-4) | Nessus | Ubuntu Local Security Checks | high |
121593 | Ubuntu 18.04 LTS : linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities (USN-3871-3) | Nessus | Ubuntu Local Security Checks | high |
121592 | Ubuntu 18.04 LTS : Linux kernel regression (USN-3871-2) | Nessus | Ubuntu Local Security Checks | high |
121469 | Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-3871-1) | Nessus | Ubuntu Local Security Checks | high |
120082 | SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2018:2380-1) (Foreshadow) | Nessus | SuSE Local Security Checks | medium |
118034 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:3084-1) | Nessus | SuSE Local Security Checks | high |
118033 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:3083-1) | Nessus | SuSE Local Security Checks | high |
117824 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:2908-1) | Nessus | SuSE Local Security Checks | high |
117800 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:2858-1) | Nessus | SuSE Local Security Checks | high |
117629 | SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2018:2776-1) | Nessus | SuSE Local Security Checks | high |
112112 | Ubuntu 14.04 LTS : Linux kernel (Xenial HWE) vulnerabilities (USN-3753-2) | Nessus | Ubuntu Local Security Checks | high |
112111 | Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-3753-1) | Nessus | Ubuntu Local Security Checks | high |
111997 | openSUSE Security Update : the Linux Kernel (openSUSE-2018-885) (Foreshadow) | Nessus | SuSE Local Security Checks | high |
111812 | openSUSE Security Update : the Linux Kernel (openSUSE-2018-886) (Foreshadow) | Nessus | SuSE Local Security Checks | high |
111165 | Debian DLA-1423-1 : linux-4.9 new package (Spectre) | Nessus | Debian Local Security Checks | high |