CVE-2018-20669
Vulnerability Summary
Timeline
Description
An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kernel memory, resulting in a Denial of Service or privilege escalation.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.58%• Percentile: 46%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Systems
- canonical•ubuntu_linux
14.04 | 16.04 | 18.04
- debian•linux
< 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1
- ubuntu•linux
< 4.15.0-115.116
- ubuntu•linux-aws
< 4.15.0-1080.84
- ubuntu•linux-aws-fips
< 4.15.0-2025.25 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1080.84~16.04.1
- ubuntu•linux-azure
< 4.15.0-1093.103~14.04.1 | < 4.15.0-1093.103~16.04.1 | < 5.0.0-1014.14~18.04.1
- ubuntu•linux-azure-4.15
< 4.15.0-1093.103
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fips
< 4.15.0-2007.8 | all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.15.0-1039.44
- ubuntu•linux-gcp
< 4.15.0-1081.92~16.04.1 | < 5.0.0-1020.20~18.04.1
- ubuntu•linux-gcp-4.15
< 4.15.0-1081.92
- ubuntu•linux-gcp-fips
all
- ubuntu•linux-gke-4.15
< 4.15.0-1067.70
- ubuntu•linux-hwe
< 4.15.0-115.116~16.04.1 | < 5.0.0-23.24~18.04.1
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.15.0-1072.73
- ubuntu•linux-oem
< 4.15.0-1094.104
- ubuntu•linux-oracle
< 4.15.0-1051.55~16.04.1 | < 4.15.0-1051.55
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.15.0-1068.72
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all
- ubuntu•linux-snapdragon
< 4.15.0-1084.92
- linux•linux_kernel
≥ 4.13, < 4.14.185 | ≥ 4.15, < 4.19.129 | ≥ 4.20, < 5.0
- netapp•cn1610_firmware
na
- netapp•hci_management_node
na
- netapp•snapprotect
na
- netapp•solidfire
na
References (14)
- http://www.securityfocus.com/bid/106748
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/log/drivers/gpu/drm/i915/i915_gem_execbuffer.c
- http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00042.html
- http://www.openwall.com/lists/oss-security/2019/01/23/6
- https://access.redhat.com/security/cve/cve-2018-20669
- https://security.netapp.com/advisory/ntap-20190404-0002/
- https://support.f5.com/csp/article/K32059550
- https://usn.ubuntu.com/4485-1/
- https://ubuntu.com/security/CVE-2018-20669
- https://www.openwall.com/lists/oss-security/2019/01/23/6
- https://www.openwall.com/lists/oss-security/2019/02/07/1
- https://ubuntu.com/security/notices/USN-4485-1
- https://www.cve.org/CVERecord?id=CVE-2018-20669
- https://security-tracker.debian.org/tracker/CVE-2018-20669