kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c
Published Dec 4, 2018
4.7
MEDIUMCVSS 3.0
EPSS 0.45%
Description
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
Affected products
No data.
Configuration 1
- < 4.19.3
Configuration 2
- 14.04
- 16.04
- 18.04
- 18.10
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.el8
Fixed · RHSA-2019:3517
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.rt24.93.el8
Fixed · RHSA-2019:3309
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.el8 | Fixed | RHSA-2019:3517 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.rt24.93.el8 | Fixed | RHSA-2019:3309 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f43f39958beb206b53292801e216d9b8a660f087 x_refsource_MISCPatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3309 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3517 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-19854 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1656986 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-11529 Advisory
- https://github.com/torvalds/linux/commit/f43f39958beb206b53292801e216d9b8a660f087 x_refsource_MISCPatchThird Party Advisory
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.3 x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-19854
- https://usn.ubuntu.com/3872-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3878-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3878-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3901-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3901-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-19854
Change history (0)
No recorded changes yet.