CVE-2018-18690
Vulnerability Summary
Timeline
Description
In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an attr from short to long form.
CVSS Metrics
- v3.0•MEDIUM•Score: 5.5CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- v2.0•MEDIUM•Score: 4.9AV:L/AC:L/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 0.68%• Percentile: 51%
Techniques & Countermeasures
- CWE-754•Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
Affected Systems
- canonical•ubuntu_linux
12.04 | 14.04 | 16.04 | 18.04
- debian•linux
< 4.17.3-1 | < 4.17.3-1 | < 4.17.3-1 | < 4.17.3-1
- ubuntu•linux
< 3.13.0-164.214 | < 4.4.0-141.167 | < 4.15.0-43.46
- ubuntu•linux-aws
< 4.4.0-1037.40 | < 4.4.0-1074.84 | < 4.15.0-1031.33
- ubuntu•linux-azure
< 4.15.0-1036.38~14.04.2 | < 4.15.0-1036.38~16.04.1 | < 4.15.0-1036.38
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-fips
< 4.4.0-1008.10
- ubuntu•linux-gcp
< 4.15.0-1026.27~16.04.1 | < 4.15.0-1026.27
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gke
all
- ubuntu•linux-hwe
< 4.15.0-43.46~16.04.1
- ubuntu•linux-hwe-6.11
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1039.45 | < 4.15.0-1028.28
- ubuntu•linux-lowlatency-hwe-6.11
all
- ubuntu•linux-lts-xenial
< 4.4.0-141.167~14.04.1
- ubuntu•linux-oem
< 4.15.0-1030.35
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1102.110 | < 4.15.0-1030.32 | all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1106.111
- debian•debian_linux
8.0
- linux•linux_kernel
< 4.17
References (25)
- https://usn.ubuntu.com/3848-2/
- https://usn.ubuntu.com/3847-1/
- https://usn.ubuntu.com/3847-2/
- https://usn.ubuntu.com/3849-1/
- https://usn.ubuntu.com/3849-2/
- https://usn.ubuntu.com/3848-1/
- https://usn.ubuntu.com/3847-3/
- https://bugzilla.suse.com/show_bug.cgi?id=1105025
- http://www.securityfocus.com/bid/105753
- https://bugzilla.kernel.org/show_bug.cgi?id=199119
- https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7b38460dc8e4eafba06c78f8e37099d3b34d473c
- https://github.com/torvalds/linux/commit/7b38460dc8e4eafba06c78f8e37099d3b34d473c
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html
- https://ubuntu.com/security/CVE-2018-18690
- https://ubuntu.com/security/notices/USN-3847-1
- https://ubuntu.com/security/notices/USN-3847-2
- https://ubuntu.com/security/notices/USN-3847-3
- https://ubuntu.com/security/notices/USN-3848-1
- https://ubuntu.com/security/notices/USN-3848-2
- https://ubuntu.com/security/notices/USN-3849-1
- https://ubuntu.com/security/notices/USN-3849-2
- https://www.cve.org/CVERecord?id=CVE-2018-18690
- https://security-tracker.debian.org/tracker/CVE-2018-18690