kernel: cleancache: Infoleak of deleted files after reuse of old inodes
Published Nov 26, 2018
5.5
MEDIUMCVSS 3.0
EPSS 0.53%
Description
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of the new one.
Affected products
- Vendor n/a Product Kernel: Defaultn/a
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| n/a | Kernel: | n/a |
|
Configuration 1
- ≤ 4.14
Configuration 2
- 7.0
Configuration 3
- 14.04
- 16.04
Configuration 4
- 8.0
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel-rt
Will not fix
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- http://www.securityfocus.com/bid/106009 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-16862 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1649017 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16862 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html mailing-listx_refsource_MLIST
- https://lore.kernel.org/patchwork/patch/1011367/ x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-16862
- https://seclists.org/oss-sec/2018/q4/169 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://usn.ubuntu.com/3879-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3879-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4094-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4118-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-16862
Change history (0)
No recorded changes yet.