CVE-2018-13096

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory access and BUG) can occur upon encountering an abnormal bitmap size when mounting a crafted f2fs image.

References

http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html

http://packetstormsecurity.com/files/151420/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html

https://bugzilla.kernel.org/show_bug.cgi?id=200167

https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=e34438c903b653daca2b2a7de95aed46226f8ed3

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e34438c903b653daca2b2a7de95aed46226f8ed3

https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html

https://seclists.org/bugtraq/2019/Jan/52

https://usn.ubuntu.com/3821-1/

https://usn.ubuntu.com/3821-2/

https://usn.ubuntu.com/4094-1/

https://usn.ubuntu.com/4118-1/

Details

Source: MITRE

Published: 2018-07-03

Updated: 2021-01-05

Type: CWE-787

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (8 total)

IDNameProductFamilySeverity
128478Ubuntu 16.04 LTS / 18.04 LTS : linux-aws vulnerabilities (USN-4118-1)NessusUbuntu Local Security Checks
critical
127889Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4094-1)NessusUbuntu Local Security Checks
high
124972EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1519)NessusHuawei Local Security Checks
high
122879Debian DLA-1715-1 : linux-4.9 security update (Spectre)NessusDebian Local Security Checks
high
121505Slackware 14.2 : Slackware 14.2 kernel (SSA:2019-030-01)NessusSlackware Local Security Checks
high
118972Ubuntu 14.04 LTS : Linux kernel (Xenial HWE) vulnerabilities (USN-3821-2)NessusUbuntu Local Security Checks
medium
118971Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-3821-1)NessusUbuntu Local Security Checks
medium
118194openSUSE Security Update : the Linux Kernel (openSUSE-2018-1184)NessusSuSE Local Security Checks
high