Back

MEDIUM

kernel: out-of-bound read in memcpy_fromiovecend()

Published Jan 3, 2019

Description

A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a system halt by accessing invalid memory address. This issue only affects kernel version 3.10.x as shipped with Red Hat Enterprise Linux 7.

Affected products

Remediation

Red Hat statement

This is an Important flaw in the Linux kernel that allows a local unprivileged user to trigger an out-of-bounds read. Successful exploitation could lead to a system halt, or potentially disclose kernel memory to userspace, but the high attack complexity makes it difficult to reliably achieve. Exploit code for this vulnerability is available.

Metrics

References (8)

Change history (6)
  1. MITRE
    • CVSS severity changed from HIGH to MEDIUM
    • CVSS vector changed from CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H to CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
    • CVSS score changed from 7.1 to 4.7
  2. REDHAT
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H to CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
    • CVSS score changed from 4.7 to 7.1
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 3, 2019
Updated Aug 5, 2024
Reserved Sep 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 21, 2018