A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry function and a denial of service or unspecified other impact may occur by renaming a file in a crafted ext4 filesystem image.
http://patchwork.ozlabs.org/patch/928666/
http://patchwork.ozlabs.org/patch/928667/
http://www.securityfocus.com/bid/104902
https://access.redhat.com/errata/RHSA-2018:2948
https://access.redhat.com/errata/RHSA-2018:3083
https://access.redhat.com/errata/RHSA-2018:3096
https://bugzilla.kernel.org/show_bug.cgi?id=200001
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10879
https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html
https://usn.ubuntu.com/3753-1/
https://usn.ubuntu.com/3753-2/
https://usn.ubuntu.com/3871-1/
https://usn.ubuntu.com/3871-3/
Source: MITRE
Published: 2018-07-26
Updated: 2019-10-09
Type: CWE-416
Base Score: 6.1
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:C
Impact Score: 8.5
Exploitability Score: 3.9
Severity: MEDIUM
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.8
Severity: HIGH
OR
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
OR
OR
OR
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
128842 | EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-1919) | Nessus | Huawei Local Security Checks | high |
124976 | EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1523) | Nessus | Huawei Local Security Checks | critical |
124830 | EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1507) | Nessus | Huawei Local Security Checks | high |
124430 | EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-1303) | Nessus | Huawei Local Security Checks | medium |
123961 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2019-4600) | Nessus | Oracle Linux Local Security Checks | medium |
123909 | EulerOS Virtualization 2.5.4 : kernel (EulerOS-SA-2019-1223) | Nessus | Huawei Local Security Checks | medium |
123906 | EulerOS Virtualization 2.5.3 : kernel (EulerOS-SA-2019-1220) | Nessus | Huawei Local Security Checks | medium |
123605 | EulerOS 2.0 SP2 : kernel (EulerOS-SA-2019-1131) | Nessus | Huawei Local Security Checks | high |
123482 | OracleVM 3.4 : Unbreakable / etc (OVMSA-2019-0011) | Nessus | OracleVM Local Security Checks | medium |
123269 | openSUSE Security Update : the Linux Kernel (openSUSE-2019-618) (Foreshadow) | Nessus | SuSE Local Security Checks | medium |
123145 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2019-4594) | Nessus | Oracle Linux Local Security Checks | medium |
122052 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS : linux-azure vulnerabilities (USN-3871-5) | Nessus | Ubuntu Local Security Checks | high |
122007 | Photon OS 2.0: Linux PHSA-2018-2.0-0109 | Nessus | PhotonOS Local Security Checks | high |
121890 | Photon OS 1.0: Linux PHSA-2018-1.0-0188 | Nessus | PhotonOS Local Security Checks | medium |
121594 | Ubuntu 16.04 LTS : linux-hwe, linux-aws-hwe, linux-gcp vulnerabilities (USN-3871-4) | Nessus | Ubuntu Local Security Checks | high |
121593 | Ubuntu 18.04 LTS : linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities (USN-3871-3) | Nessus | Ubuntu Local Security Checks | high |
121592 | Ubuntu 18.04 LTS : Linux kernel regression (USN-3871-2) | Nessus | Ubuntu Local Security Checks | high |
121469 | Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-3871-1) | Nessus | Ubuntu Local Security Checks | high |
120082 | SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2018:2380-1) (Foreshadow) | Nessus | SuSE Local Security Checks | medium |
119187 | Scientific Linux Security Update : kernel on SL7.x x86_64 (20181030) | Nessus | Scientific Linux Local Security Checks | high |
118990 | CentOS 7 : kernel (CESA-2018:3083) | Nessus | CentOS Local Security Checks | high |
118770 | Oracle Linux 7 : kernel (ELSA-2018-3083) | Nessus | Oracle Linux Local Security Checks | high |
118528 | RHEL 7 : kernel-rt (RHSA-2018:3096) | Nessus | Red Hat Local Security Checks | high |
118525 | RHEL 7 : kernel (RHSA-2018:3083) | Nessus | Red Hat Local Security Checks | high |
118513 | RHEL 7 : kernel-alt (RHSA-2018:2948) (Spectre) | Nessus | Red Hat Local Security Checks | high |
118034 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:3084-1) | Nessus | SuSE Local Security Checks | high |
118033 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:3083-1) | Nessus | SuSE Local Security Checks | high |
117881 | Photon OS 1.0: Linux PHSA-2018-1.0-0188 (deprecated) | Nessus | PhotonOS Local Security Checks | medium |
117824 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:2908-1) | Nessus | SuSE Local Security Checks | high |
117800 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:2858-1) | Nessus | SuSE Local Security Checks | high |
117629 | SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2018:2776-1) | Nessus | SuSE Local Security Checks | high |
112112 | Ubuntu 14.04 LTS : Linux kernel (Xenial HWE) vulnerabilities (USN-3753-2) | Nessus | Ubuntu Local Security Checks | high |
112111 | Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-3753-1) | Nessus | Ubuntu Local Security Checks | high |
111997 | openSUSE Security Update : the Linux Kernel (openSUSE-2018-885) (Foreshadow) | Nessus | SuSE Local Security Checks | high |
111812 | openSUSE Security Update : the Linux Kernel (openSUSE-2018-886) (Foreshadow) | Nessus | SuSE Local Security Checks | high |
111165 | Debian DLA-1423-1 : linux-4.9 new package (Spectre) | Nessus | Debian Local Security Checks | high |