CVE-2018-25020
Vulnerability Summary
Timeline
Description
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 0.51%• Percentile: 42%
Techniques & Countermeasures
- CWE-120•Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Affected Systems
- debian•linux
< 4.17.3-1 | < 4.17.3-1 | < 4.17.3-1 | < 4.17.3-1
- ubuntu•linux
< 4.15.0-166.174
- ubuntu•linux-aws
< 4.15.0-1118.125
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-fips
< 4.15.0-2059.61 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1118.125~16.04.1
- ubuntu•linux-azure
< 4.15.0-1129.142~14.04.1 | < 4.15.0-1129.142~16.04.1 | all
- ubuntu•linux-azure-4.15
< 4.15.0-1129.142
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fips
< 4.15.0-2041.45 | all
- ubuntu•linux-bluefield
all
- ubuntu•linux-dell300x
< 4.15.0-1033.38
- ubuntu•linux-fips
< 4.15.0-1075.84 | all
- ubuntu•linux-gcp
< 4.15.0-1114.128~16.04.1 | all
- ubuntu•linux-gcp-4.15
< 4.15.0-1114.128
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-fips
< 4.15.0-2024.26 | all
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-hwe
< 4.15.0-166.174~16.04.1 | all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-5.13
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.15.0-1105.107
- ubuntu•linux-oem
all
- ubuntu•linux-oem-5.6
all
- ubuntu•linux-oracle
< 4.15.0-1085.93~16.04.1 | < 4.15.0-1085.93
- ubuntu•linux-oracle-5.0
all
- ubuntu•linux-oracle-5.3
all
- ubuntu•linux-oracle-5.8
all
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.15.0-1101.108 | all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all
- ubuntu•linux-riscv-5.8
all
- ubuntu•linux-snapdragon
< 4.15.0-1118.127
- linux•linux_kernel
< 4.17
- netapp•cloud_backup
na
- netapp•h300e_firmware
na
- netapp•h300s_firmware
na
- netapp•h410c_firmware
na
- netapp•h410s_firmware
na
- netapp•h500e_firmware
na
- netapp•h500s_firmware
na
Showing first 50 affected entries in server-rendered view.
References (7)
- https://github.com/torvalds/linux/commit/050fad7c4534c13c8eb1d9c2ba66012e014773cb
- https://security.netapp.com/advisory/ntap-20211229-0005/
- http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.html
- https://ubuntu.com/security/CVE-2018-25020
- https://git.kernel.org/linus/050fad7c4534c13c8eb1d9c2ba66012e014773cb
- https://www.cve.org/CVERecord?id=CVE-2018-25020
- https://security-tracker.debian.org/tracker/CVE-2018-25020