Back

HIGH

kernel: Arbitrary Kernel Read into dmesg via Missing Address Check in segfault Handler

Published Oct 8, 2018

Description

A missing address check in the callers of the show_opcodes() in the Linux kernel allows an attacker to dump the kernel memory at an arbitrary kernel address into the dmesg log.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (6)
  1. MITRE
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N to CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
    • CVSS score changed from 4.7 to 7
  2. REDHAT
    • CVSS severity changed from HIGH to MEDIUM
    • CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H to CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
    • CVSS score changed from 7 to 4.7
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 8, 2018
Updated Aug 5, 2024
Reserved Jul 27, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 13, 2018