CVE-2018-10840

Aliases:DEBIAN-CVE-2018-10840CGA-2687-vprm-7w2wCGA-2c8r-2jv6-2hm3CGA-2jj8-4h4r-4jrrCGA-34vg-4j2j-5rmfCGA-3gc4-cx3w-p8cjCGA-3mx7-9w77-mr5qCGA-3wcf-jv9q-pr5fCGA-3x4q-79c9-c8g9CGA-439w-pgp9-2wrgCGA-4492-mchq-cf9mCGA-4752-f26v-2c68CGA-4gxp-q93g-36rcCGA-4h63-jw8w-668fCGA-4x9j-qjmc-xcxhCGA-4xxw-j682-vfjcCGA-5793-cc6j-6f7mCGA-59g9-6254-qj8hCGA-59mc-gf6m-x5gmCGA-5c26-c579-pgr3CGA-5mj7-hqm4-mmcwCGA-6m49-9v8f-m929CGA-6mg2-9fwr-95mgCGA-6p78-676w-6g4mCGA-6q57-f29x-qc79CGA-6x2g-7pjf-8wr5CGA-7382-v4c5-c6jgCGA-7fj9-p68m-5wc6CGA-7rc4-ggxr-jw8vCGA-7v5f-2gqj-8f73CGA-84fm-wwgw-rvfqCGA-85vm-xpg9-xv38CGA-8898-r5jh-76vrCGA-8c7c-9w9w-7p5hCGA-9247-w93j-mp4pCGA-93q5-mv5g-gf6mCGA-9947-r35g-qmxqCGA-9cv8-99qc-xr7pCGA-9fcq-hpc8-c76jCGA-9jcx-w64p-8m9pCGA-9jww-prh9-j2hpCGA-9qcf-7m9v-4c85CGA-9rvj-8585-3x92CGA-9v66-f73r-69p7CGA-c25p-j345-4f7mCGA-ccfh-m7vc-45hmCGA-cfwg-hvx2-wf34CGA-ch8h-fff6-87f2CGA-cp9m-vf3f-cgxjCGA-cqfj-99j2-h6vpCGA-f9wc-v835-rjr7CGA-fgj9-4f94-3j5gCGA-fm3j-m8qj-pcgqCGA-fw3h-2q2c-hq3xCGA-g63v-9p62-qgwxCGA-gj79-g9cm-qfj8CGA-gpqj-8w8x-qw33CGA-gqgp-vvj4-cgx9CGA-gw62-c6xg-cqp3CGA-h2pw-g44f-2q8fCGA-h35g-2xv2-3q89CGA-hcj4-cv9j-6fg4CGA-hhgx-3w4x-j7gpCGA-hhpw-q5v9-pwwmCGA-hw82-5gv5-7qp3CGA-j4j8-r73h-4mmjCGA-j752-jpjw-phhqCGA-jch3-928j-hf89CGA-jh4r-r695-f5mxCGA-jp24-mq67-3ff7CGA-jp9j-4r79-3hc7CGA-jw58-8hf5-rmchCGA-m4cc-8f5c-pr53CGA-m7wq-vqjf-wvmpCGA-mg4j-xrjm-v46mCGA-mg8g-5rgq-q863CGA-mqgc-x4pq-779rCGA-mqx4-wmrr-xgvmCGA-mrfg-cmf2-59pcCGA-mwf3-cpcf-pc56CGA-p25q-ffp3-8chgCGA-p3j6-jx54-v66qCGA-p6hc-hxwq-w8gfCGA-p723-qhhw-fxmrCGA-pgff-mww7-cpp7CGA-phpw-g473-4jf4CGA-pp8g-382w-mh5rCGA-pwwm-fx68-8g8vCGA-px6c-5gh3-9f96CGA-pxmm-w5xc-r6wfCGA-q66w-6j8x-x3c9CGA-q7jg-4ffm-cgvwCGA-qf79-v54r-x7vpCGA-qpqp-4vxh-52mgCGA-qr8q-pxj4-5v7hCGA-r532-5rff-9vp8CGA-r79x-v8wg-fc43CGA-r96j-cm72-v9v7CGA-rcfh-7q2p-r5gmCGA-rf3g-vx55-hpr8CGA-rvhj-9hv5-h8r8CGA-rw37-6qfj-89ggCGA-v4fm-6gpm-6xm5CGA-v5m2-qmrq-fpm9CGA-vgc9-52mp-h3hvCGA-vgpf-6v9v-q7mxCGA-vh99-27mh-9cmjCGA-vrmj-prhr-28gwCGA-vvw9-jgx7-mj7vCGA-w2gp-53vx-46rjCGA-w4xq-whw3-977hCGA-w85p-g58j-9rmgCGA-w99h-q2mc-9vrxCGA-wwfv-27mw-fxx6CGA-x2p3-5p8x-qhgcCGA-5r88-c22q-3jhcCGA-m4jq-v32x-8g94CGA-247j-89vh-xhcwCGA-2wqc-2724-2gp3CGA-33ph-w648-8chxCGA-7gwr-f6cv-54wcCGA-9r9p-9633-xr74CGA-cv64-h7w6-5vh5CGA-cvch-pq58-xp8wCGA-j6c8-qq6r-2m7mCGA-m8m9-5rr8-v6jrCGA-mq35-675x-xrcfCGA-q35v-94p7-c3x2CGA-q545-vrgx-528fCGA-r6cq-g4f6-p3x8CGA-rqhr-g566-fwq3CGA-v84j-3h3v-rvhxCGA-4xm5-8m9m-r2frCGA-7jcw-7mff-58gcCGA-8gpf-wm3x-92rgCGA-9x8g-gxr9-5c2wCGA-mcc9-hjmp-6mcqCGA-crvx-pc29-9975CGA-3ffq-crv5-6m9rCGA-c25h-33g9-7xr3CGA-qf8w-25v3-hhj9
Modified
Published: 16 Jul 2018, 20:00
Last modified:05 Aug 2024, 07:46

Vulnerability Summary

Overall Risk (default)
medium
39/100
CVSS Score
7.2 HIGH
v2.0 (nvd)
EPSS Score
0.67% LOW
1% probability +0.57%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

16 Jul 2018, 20:00
Published
Vulnerability first disclosed
05 Aug 2024, 07:46
Last Modified
Vulnerability information updated

Description

Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.

CVSS Metrics

  • v3.1MEDIUMScore: 6.6CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.0MEDIUMScore: 5.2CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.67% Percentile: 50%

Techniques & Countermeasures

  • CWE-122Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • chainguardhyperv-daemons-6.18

    < 0

  • chainguardhyperv-daemons-generic

    < 0

  • chainguardlinux-aws-6.12

    < 6.12.65-r0 | < 0

  • chainguardlinux-aws-6.12-boot-installed

    < 0

  • chainguardlinux-aws-6.12-fips-boot-installed

    < 0

  • chainguardlinux-aws-6.12-headers

    < 0

  • chainguardlinux-aws-6.12-modules

    < 0

  • chainguardlinux-aws-6.18

    < 0 | < 6.18.10-r0

  • chainguardlinux-aws-6.18-boot-installed

    < 0

  • chainguardlinux-aws-6.18-fips-boot-installed

    < 0

  • chainguardlinux-aws-6.18-headers

    < 0

  • chainguardlinux-aws-6.18-modules

    < 0

  • chainguardlinux-aws-generic

    < 0 | < 6.18.5-r0

  • chainguardlinux-aws-generic-boot-installed

    < 0

  • chainguardlinux-aws-generic-fips-boot-installed

    < 0

  • chainguardlinux-aws-generic-headers

    < 0

  • chainguardlinux-aws-generic-modules

    < 0

  • chainguardlinux-azure-6.12

    < 6.12.65-r1 | < 0

  • chainguardlinux-azure-6.18

    < 0

  • chainguardlinux-azure-6.18-boot-installed

    < 0

  • chainguardlinux-azure-6.18-fips-boot-installed

    < 0

  • chainguardlinux-azure-6.18-headers

    < 0

  • chainguardlinux-azure-6.18-modules

    < 0

  • chainguardlinux-azure-generic

    < 6.18.5-r0 | < 0

  • chainguardlinux-azure-generic-boot-installed

    < 0

  • chainguardlinux-azure-generic-fips-boot-installed

    < 0

  • chainguardlinux-azure-generic-headers

    < 0

  • chainguardlinux-azure-generic-modules

    < 0

  • chainguardlinux-desktop-6.18

    all

  • chainguardlinux-desktop-6.18-bootc

    all

  • chainguardlinux-desktop-6.18-bootc-boot-installed

    all

  • chainguardlinux-desktop-6.18-headers

    all

  • chainguardlinux-desktop-6.18-modules

    all

  • chainguardlinux-desktop-7.2

    all

  • chainguardlinux-desktop-7.2-bootc

    all

  • chainguardlinux-desktop-7.2-bootc-boot-installed

    all

  • chainguardlinux-desktop-7.2-modules

    all

  • chainguardlinux-firecracker-6.18

    all

  • chainguardlinux-gcp-6.12

    < 6.12.65-r0 | < 0

  • chainguardlinux-gcp-6.18

    < 0 | < 6.18.10-r0

  • chainguardlinux-gcp-6.18-boot-installed

    < 0

  • chainguardlinux-gcp-6.18-fips-boot-installed

    < 0

  • chainguardlinux-gcp-6.18-headers

    < 0

  • chainguardlinux-gcp-6.18-modules

    < 0

  • chainguardlinux-gcp-generic

    < 6.18.5-r0 | < 0

  • chainguardlinux-gcp-generic-boot-installed

    < 0

  • chainguardlinux-gcp-generic-fips-boot-installed

    < 0

  • chainguardlinux-gcp-generic-headers

    < 0

  • chainguardlinux-gcp-generic-modules

    < 0

  • chainguardlinux-qemu-6.12

    < 6.12.71-r0

Showing first 50 affected entries in server-rendered view.

References (7)