CVE-2018-14633

Description

A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depending on how the targets code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead to a system crash and thus to a denial-of-service or possibly to a non-authorized access to data exported by an iSCSI target. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is highly unlikely. Kernel versions 4.18.x, 4.14.x and 3.10.x are believed to be vulnerable.

Risk Information

Base Score
7.0
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
EPSS Score
Exploitation Probability
7.984

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel for Microsoft Azure Cloud systems (USN-3752-3) linux-image-oem_4.15.0.1021.23_amd64.debLinux
Linux kernel (USN-3775-1) linux-image-3.13.0-160-generic_3.13.0-160.210_i386.debLinux
Linux kernel (USN-3775-1) linux-image-3.13.0-160-generic_3.13.0-160.210_amd64.debLinux
Linux kernel (USN-3775-1) linux-image-3.13.0-160-lowlatency_3.13.0-160.210_i386.debLinux
Linux kernel (USN-3775-1) linux-image-3.13.0-160-lowlatency_3.13.0-160.210_amd64.debLinux
Linux kernel (USN-3776-1) linux-image-aws_4.4.0.1069.71_amd64.debLinux
Linux kernel (USN-3776-1) linux-image-kvm_4.4.0.1035.34_amd64.debLinux
Linux kernel (USN-3776-1) linux-image-generic_4.4.0.137.143_i386.debLinux
Linux kernel (USN-3776-1) linux-image-generic_4.4.0.137.143_amd64.debLinux
Linux kernel (USN-3776-1) linux-image-lowlatency_4.4.0.137.143_i386.debLinux
Linux kernel (USN-3776-1) linux-image-lowlatency_4.4.0.137.143_amd64.debLinux
Linux kernel (USN-3776-1) linux-image-4.4.0-1035-kvm_4.4.0-1035.41_amd64.debLinux
Linux kernel (USN-3776-1) linux-image-4.4.0-1069-aws_4.4.0-1069.79_amd64.debLinux
Linux kernel (USN-3776-1) linux-image-4.4.0-137-generic_4.4.0-137.163_i386.debLinux
Linux kernel (USN-3776-1) linux-image-4.4.0-137-generic_4.4.0-137.163_amd64.debLinux
Linux kernel (USN-3776-1) linux-image-4.4.0-137-lowlatency_4.4.0-137.163_i386.debLinux
Linux kernel (USN-3776-1) linux-image-4.4.0-137-lowlatency_4.4.0-137.163_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3776-2) linux-image-aws_4.4.0.1031.31_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3776-2) linux-image-4.4.0-1031-aws_4.4.0-1031.34_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3776-2) linux-image-4.4.0-137-generic_4.4.0-137.163~14.04.1_i386.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3776-2) linux-image-4.4.0-137-generic_4.4.0-137.163~14.04.1_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3776-2) linux-image-4.4.0-137-lowlatency_4.4.0-137.163~14.04.1_i386.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3776-2) linux-image-4.4.0-137-lowlatency_4.4.0-137.163~14.04.1_amd64.debLinux
Linux kernel (USN-3777-1) linux-image-oem_4.15.0.1021.23_amd64.debLinux
Linux kernel (USN-3777-1) linux-image-4.15.0-1021-gcp_4.15.0-1021.22_amd64.debLinux
Linux kernel (USN-3777-1) linux-image-4.15.0-1021-oem_4.15.0-1021.24_amd64.debLinux
Linux kernel (USN-3777-1) linux-image-4.15.0-1023-aws_4.15.0-1023.23_amd64.debLinux
Linux kernel (USN-3777-1) linux-image-4.15.0-1023-kvm_4.15.0-1023.23_amd64.debLinux
Linux kernel (USN-3777-1) linux-image-4.15.0-36-generic_4.15.0-36.39_i386.debLinux
Linux kernel (USN-3777-1) linux-image-4.15.0-36-generic_4.15.0-36.39_amd64.debLinux
Linux kernel (USN-3777-1) linux-image-4.15.0-36-lowlatency_4.15.0-36.39_i386.debLinux
Linux kernel (USN-3777-1) linux-image-4.15.0-36-lowlatency_4.15.0-36.39_amd64.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-oem_4.15.0.36.59_amd64.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-4.15.0-1021-gcp_4.15.0-1021.22~16.04.1_amd64.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-4.15.0-36-generic_4.15.0-36.39~16.04.1_i386.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-4.15.0-36-generic_4.15.0-36.39~16.04.1_amd64.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-generic-hwe-16.04_4.15.0.36.59_i386.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-generic-hwe-16.04_4.15.0.36.59_amd64.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-4.15.0-36-lowlatency_4.15.0-36.39~16.04.1_i386.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-4.15.0-36-lowlatency_4.15.0-36.39~16.04.1_amd64.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-lowlatency-hwe-16.04_4.15.0.36.59_i386.debLinux
Linux kernel for Google Cloud Platform (GCP) systems (USN-3777-2) linux-image-lowlatency-hwe-16.04_4.15.0.36.59_amd64.debLinux
Linux kernel for Microsoft Azure Cloud systems (USN-3777-3) linux-image-azure_4.15.0.1025.31_amd64.debLinux
Linux kernel for Microsoft Azure Cloud systems (USN-3777-3) linux-image-4.15.0-1025-azure_4.15.0-1025.26_amd64.debLinux
Linux kernel for Microsoft Azure Cloud systems (USN-3777-3) linux-image-4.15.0-1025-azure_4.15.0-1025.26~16.04.1_amd64.debLinux
Kernel security update (CESA-2018:2384) kernel-debug-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:2384) kernel-debug-devel-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) perf-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) kernel-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) bpftool-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) python-perf-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) kernel-debug-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) kernel-devel-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) kernel-tools-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) kernel-headers-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) kernel-tools-libs-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) kernel-debug-devel-3.10.0-957.1.3.el7.x86_64.rpmLinux
Kernel security update (CESA-2018:3651) kernel-tools-libs-devel-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update bpftool-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-abi-whitelists-3.10.0-957.1.3.el7.noarch.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-debug-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-debug-devel-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-devel-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-doc-3.10.0-957.1.3.el7.noarch.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-headers-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-tools-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-tools-libs-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update kernel-tools-libs-devel-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update perf-3.10.0-957.1.3.el7.x86_64.rpmLinux
(RHSA-2018:3651) kernel security, bug fix, and enhancement update python-perf-3.10.0-957.1.3.el7.x86_64.rpmLinux
SUSE-SU-2018:3618-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-bigsmp-extra-3.0.101-0.47.106.56.1.x86_64.rpmLinux
SUSE-SU-2018:3618-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-0.47.106.56.1.i586.rpmLinux
SUSE-SU-2018:3618-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-0.47.106.56.1.x86_64.rpmLinux
SUSE-SU-2018:3618-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-pae-extra-3.0.101-0.47.106.56.1.i586.rpmLinux
SUSE-SU-2018:3618-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-trace-extra-3.0.101-0.47.106.56.1.x86_64.rpmLinux
SUSE-SU-2018:3618-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-0.47.106.56.1.i586.rpmLinux
SUSE-SU-2018:3618-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-0.47.106.56.1.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-debuginfo-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-debugsource-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-devel-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-extra-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-extra-debuginfo-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-devel-4.4.162-94.69.2.noarch.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-macros-4.4.162-94.69.2.noarch.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-source-4.4.162-94.69.2.noarch.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-syms-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-default-base-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-default-base-debuginfo-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) lttng-modules-2.7.1-8.6.1.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) lttng-modules-debugsource-2.7.1-8.6.1.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) lttng-modules-kmp-default-2.7.1_k4.4.162_94.69-8.6.1.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) lttng-modules-kmp-default-debuginfo-2.7.1_k4.4.162_94.69-8.6.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-pae-extra-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-trace-extra-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-default-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-default-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-default-base-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-default-base-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-default-devel-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-default-devel-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-ec2-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-ec2-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-ec2-base-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-ec2-base-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-ec2-devel-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-ec2-devel-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-pae-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-pae-base-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-pae-devel-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-source-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-source-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-syms-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-syms-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-trace-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-trace-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-trace-base-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-trace-base-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-trace-devel-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-trace-devel-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-xen-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-xen-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-xen-base-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-xen-base-3.0.101-108.81.1.x86_64.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-xen-devel-3.0.101-108.81.1.i586.rpmLinux
SUSE-SU-2018:3746-1(SUSE Linux Enterprise Server 11-SP4 ) kernel-xen-devel-3.0.101-108.81.1.x86_64.rpmLinux
(CESA-2018:3651) kernel security, bug fix, and enhancement update bpftool-3.10.0-957.1.3.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234