kernel: Memory corruption in JFS setattr
Published Jun 12, 2018
7.8
HIGHCVSS 3.1
EPSS 2.37%
Description
In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability can be triggered by an unprivileged user with the ability to create files and execute programs. A kmalloc call is incorrect, leading to slab-out-of-bounds in jfs_xattr.
Affected products
No data.
Configuration 1
- ≥ 2.6.12 · < 3.16.58
- ≥ 3.17 · < 3.18.118
- ≥ 3.19 · < 4.4.147
- ≥ 4.5 · < 4.9.119
- ≥ 4.10 · < 4.14.62
- ≥ 4.15 · < 4.17.14
Configuration 2
- 14.04
- 16.04
- 18.04
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://www.securityfocus.com/bid/104452 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-12233 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1590205 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry
- https://lkml.org/lkml/2018/6/2/2 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://marc.info/?l=linux-kernel&m=152814391530549&w=2 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-12233
- https://usn.ubuntu.com/3752-1/ vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- https://usn.ubuntu.com/3752-2/ vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- https://usn.ubuntu.com/3752-3/ vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- https://usn.ubuntu.com/3753-1/ vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- https://usn.ubuntu.com/3753-2/ vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- https://usn.ubuntu.com/3754-1/ vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2018-12233
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/104452 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-12233 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1590205 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html | mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry | |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html | mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry | |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html | mailing-listx_refsource_MLISTThird Party AdvisoryVDB Entry | |
| https://lkml.org/lkml/2018/6/2/2 | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://marc.info/?l=linux-kernel&m=152814391530549&w=2 | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-12233 | ||
| https://usn.ubuntu.com/3752-1/ | vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry | |
| https://usn.ubuntu.com/3752-2/ | vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry | |
| https://usn.ubuntu.com/3752-3/ | vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry | |
| https://usn.ubuntu.com/3753-1/ | vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry | |
| https://usn.ubuntu.com/3753-2/ | vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry | |
| https://usn.ubuntu.com/3754-1/ | vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry | |
| https://www.cve.org/CVERecord?id=CVE-2018-12233 |
Change history (0)
No recorded changes yet.