A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.
http://patchwork.ozlabs.org/patch/929792/
http://www.securityfocus.com/bid/104901
https://access.redhat.com/errata/RHSA-2018:2948
https://access.redhat.com/errata/RHSA-2018:3083
https://access.redhat.com/errata/RHSA-2018:3096
https://bugzilla.kernel.org/show_bug.cgi?id=200015
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10881
https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html
https://usn.ubuntu.com/3752-1/
https://usn.ubuntu.com/3752-2/
https://usn.ubuntu.com/3752-3/
https://usn.ubuntu.com/3753-1/
Source: MITRE
Published: 2018-07-26
Updated: 2019-10-09
Type: CWE-119
Base Score: 4.9
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C
Impact Score: 6.9
Exploitability Score: 3.9
Severity: MEDIUM
Base Score: 5.5
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 1.8
Severity: MEDIUM
OR
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
OR
OR
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
124973 | EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1520) | Nessus | Huawei Local Security Checks | high |
124830 | EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1507) | Nessus | Huawei Local Security Checks | high |
124637 | OracleVM 3.4 : Unbreakable / etc (OVMSA-2019-0014) | Nessus | OracleVM Local Security Checks | high |
123961 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2019-4600) | Nessus | Oracle Linux Local Security Checks | medium |
123909 | EulerOS Virtualization 2.5.4 : kernel (EulerOS-SA-2019-1223) | Nessus | Huawei Local Security Checks | medium |
123906 | EulerOS Virtualization 2.5.3 : kernel (EulerOS-SA-2019-1220) | Nessus | Huawei Local Security Checks | medium |
123631 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2019-4596) | Nessus | Oracle Linux Local Security Checks | high |
123269 | openSUSE Security Update : the Linux Kernel (openSUSE-2019-618) (Foreshadow) | Nessus | SuSE Local Security Checks | medium |
123121 | EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-1108) | Nessus | Huawei Local Security Checks | high |
122201 | EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-1028) | Nessus | Huawei Local Security Checks | high |
120082 | SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2018:2380-1) (Foreshadow) | Nessus | SuSE Local Security Checks | medium |
119921 | EulerOS 2.0 SP2 : kernel (EulerOS-SA-2018-1432) | Nessus | Huawei Local Security Checks | high |
119187 | Scientific Linux Security Update : kernel on SL7.x x86_64 (20181030) | Nessus | Scientific Linux Local Security Checks | high |
118990 | CentOS 7 : kernel (CESA-2018:3083) | Nessus | CentOS Local Security Checks | high |
118770 | Oracle Linux 7 : kernel (ELSA-2018-3083) | Nessus | Oracle Linux Local Security Checks | high |
118528 | RHEL 7 : kernel-rt (RHSA-2018:3096) | Nessus | Red Hat Local Security Checks | high |
118525 | RHEL 7 : kernel (RHSA-2018:3083) | Nessus | Red Hat Local Security Checks | high |
118513 | RHEL 7 : kernel-alt (RHSA-2018:2948) (Spectre) | Nessus | Red Hat Local Security Checks | high |
118034 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:3084-1) | Nessus | SuSE Local Security Checks | high |
118033 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:3083-1) | Nessus | SuSE Local Security Checks | high |
117824 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:2908-1) | Nessus | SuSE Local Security Checks | high |
117800 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:2858-1) | Nessus | SuSE Local Security Checks | high |
117629 | SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2018:2776-1) | Nessus | SuSE Local Security Checks | high |
112189 | Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel (Azure, GCP, OEM) vulnerabilities (USN-3752-3) | Nessus | Ubuntu Local Security Checks | high |
112113 | Ubuntu 14.04 LTS : Linux kernel vulnerabilities (USN-3754-1) | Nessus | Ubuntu Local Security Checks | high |
112112 | Ubuntu 14.04 LTS : Linux kernel (Xenial HWE) vulnerabilities (USN-3753-2) | Nessus | Ubuntu Local Security Checks | high |
112111 | Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-3753-1) | Nessus | Ubuntu Local Security Checks | high |
112110 | Ubuntu 16.04 LTS : Linux kernel (HWE) vulnerabilities (USN-3752-2) | Nessus | Ubuntu Local Security Checks | high |
112109 | Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-3752-1) | Nessus | Ubuntu Local Security Checks | high |
111997 | openSUSE Security Update : the Linux Kernel (openSUSE-2018-885) (Foreshadow) | Nessus | SuSE Local Security Checks | high |
111812 | openSUSE Security Update : the Linux Kernel (openSUSE-2018-886) (Foreshadow) | Nessus | SuSE Local Security Checks | high |
111165 | Debian DLA-1423-1 : linux-4.9 new package (Spectre) | Nessus | Debian Local Security Checks | high |