CVE-2018-1000199

Description

The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.478

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-3207-1) linux-image-generic_3.13.0.147.157_amd64.debLinux
Linux kernel (USN-3207-1) linux-image-lowlatency_3.13.0.147.157_amd64.debLinux
Linux hardware enablement kernel from Xenial for Trusty (USN-3364-2) linux-image-generic-lts-xenial_4.4.0.124.104_amd64.debLinux
Linux hardware enablement kernel from Xenial for Trusty (USN-3364-2) linux-image-generic-lts-xenial_4.4.0.124.104_i386.debLinux
Linux hardware enablement kernel from Xenial for Trusty (USN-3364-2) linux-image-lowlatency-lts-xenial_4.4.0.124.104_amd64.debLinux
Linux hardware enablement kernel from Xenial for Trusty (USN-3364-2) linux-image-lowlatency-lts-xenial_4.4.0.124.104_i386.debLinux
Linux kernel (USN-3548-1) linux-image-lowlatency_4.13.0.41.44_i386.debLinux
Linux kernel (USN-3583-1) linux-image-generic_3.13.0.147.157_i386.debLinux
Linux kernel (USN-3583-1) linux-image-lowlatency_3.13.0.147.157_i386.debLinux
Linux hardware enablement (HWE) kernel (USN-3597-2) linux-image-generic-hwe-16.04_4.13.0.41.60_amd64.debLinux
Linux hardware enablement (HWE) kernel (USN-3597-2) linux-image-generic-hwe-16.04_4.13.0.41.60_i386.debLinux
Linux hardware enablement (HWE) kernel (USN-3597-2) linux-image-lowlatency-hwe-16.04_4.13.0.41.60_amd64.debLinux
Linux hardware enablement (HWE) kernel (USN-3597-2) linux-image-lowlatency-hwe-16.04_4.13.0.41.60_i386.debLinux
Linux kernel (USN-3641-1) linux-image-aws_4.4.0.1019.19_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-aws_4.4.0.1057.59_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-kvm_4.4.0.1023.22_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-oem_4.13.0.1026.30_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-azure_4.13.0.1016.17_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-generic_4.13.0.41.44_i386.debLinux
Linux kernel (USN-3641-1) linux-image-generic_4.13.0.41.44_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-generic_4.4.0.124.130_i386.debLinux
Linux kernel (USN-3641-1) linux-image-generic_4.4.0.124.130_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-lowlatency_4.13.0.41.44_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-lowlatency_4.4.0.124.130_i386.debLinux
Linux kernel (USN-3641-1) linux-image-lowlatency_4.4.0.124.130_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-1019-aws_4.4.0-1019.19_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-1023-kvm_4.4.0-1023.28_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-1057-aws_4.4.0-1057.66_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-1015-gcp_4.13.0-1015.19_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-1026-oem_4.13.0-1026.29_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-1016-azure_4.13.0-1016.19_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-41-generic_4.13.0-41.46_i386.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-41-generic_4.13.0-41.46_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-41-generic_4.13.0-41.46~16.04.1_i386.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-41-generic_4.13.0-41.46~16.04.1_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-124-generic_4.4.0-124.148_i386.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-124-generic_4.4.0-124.148_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-124-generic_4.4.0-124.148~14.04.1_i386.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-124-generic_4.4.0-124.148~14.04.1_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-9027-euclid_4.4.0-9027.29_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-3.13.0-147-generic_3.13.0-147.196_i386.debLinux
Linux kernel (USN-3641-1) linux-image-3.13.0-147-generic_3.13.0-147.196_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-41-lowlatency_4.13.0-41.46_i386.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-41-lowlatency_4.13.0-41.46_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-41-lowlatency_4.13.0-41.46~16.04.1_i386.debLinux
Linux kernel (USN-3641-1) linux-image-4.13.0-41-lowlatency_4.13.0-41.46~16.04.1_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-124-lowlatency_4.4.0-124.148_i386.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-124-lowlatency_4.4.0-124.148_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-124-lowlatency_4.4.0-124.148~14.04.1_i386.debLinux
Linux kernel (USN-3641-1) linux-image-4.4.0-124-lowlatency_4.4.0-124.148~14.04.1_amd64.debLinux
Linux kernel (USN-3641-1) linux-image-3.13.0-147-lowlatency_3.13.0-147.196_i386.debLinux
Linux kernel (USN-3641-1) linux-image-3.13.0-147-lowlatency_3.13.0-147.196_amd64.debLinux
(RHSA-2018:1345) Important: kernel security update kernel-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-abi-whitelists-3.10.0-693.25.4.el7.noarch.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-debug-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-debug-devel-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-devel-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-doc-3.10.0-693.25.4.el7.noarch.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-headers-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-tools-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-tools-libs-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update kernel-tools-libs-devel-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update perf-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1345) Important: kernel security update python-perf-3.10.0-693.25.4.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-abi-whitelists-3.10.0-327.66.3.el7.noarch.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-debug-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-debug-devel-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-devel-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-doc-3.10.0-327.66.3.el7.noarch.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-headers-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-tools-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-tools-libs-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update kernel-tools-libs-devel-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update perf-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1347) Important: kernel security update python-perf-3.10.0-327.66.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-abi-whitelists-3.10.0-514.48.3.el7.noarch.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-debug-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-debug-devel-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-devel-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-doc-3.10.0-514.48.3.el7.noarch.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-headers-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-tools-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-tools-libs-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update kernel-tools-libs-devel-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update perf-3.10.0-514.48.3.el7.x86_64.rpmLinux
(RHSA-2018:1348) Important: kernel security update python-perf-3.10.0-514.48.3.el7.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-debuginfo-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debuginfo-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debugsource-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-devel-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-devel-azure-4.12.14-16.16.1.noarch.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-source-azure-4.12.14-16.16.1.noarch.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-syms-azure-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-base-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-base-debuginfo-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-debuginfo-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-debugsource-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-devel-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-devel-azure-4.12.14-6.43.1.noarch.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-source-azure-4.12.14-6.43.1.noarch.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-syms-azure-4.12.14-6.43.1.x86_64.rpmLinux
Dtrace-modules-3.8.13-118.21.4.el6uek update (ELSA-2018-4134) dtrace-modules-3.8.13-118.21.4.el6uek-0.4.5-3.el6.x86_64.rpmLinux
Dtrace-modules-3.8.13-118.21.4.el7uek update (ELSA-2018-4134) dtrace-modules-3.8.13-118.21.4.el7uek-0.4.5-3.el7.x86_64.rpmLinux
Dtrace-modules-3.8.13-118.22.1.el6uek update (ELSA-2018-4164) dtrace-modules-3.8.13-118.22.1.el6uek-0.4.5-3.el6.x86_64.rpmLinux
Dtrace-modules-3.8.13-118.22.1.el7uek update (ELSA-2018-4164) dtrace-modules-3.8.13-118.22.1.el7uek-0.4.5-3.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234