CVE-2018-18690

Description

In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an attr from short to long form.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.058

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-3848-1) linux-image-aws_4.4.0.1074.76_amd64.debLinux
Linux kernel (USN-3848-1) linux-image-kvm_4.4.0.1039.38_amd64.debLinux
Linux kernel (USN-3848-1) linux-image-generic_4.4.0.141.147_i386.debLinux
Linux kernel (USN-3848-1) linux-image-generic_4.4.0.141.147_amd64.debLinux
Linux kernel (USN-3848-1) linux-image-lowlatency_4.4.0.141.147_i386.debLinux
Linux kernel (USN-3848-1) linux-image-lowlatency_4.4.0.141.147_amd64.debLinux
Linux kernel (USN-3848-1) linux-image-4.4.0-1039-kvm_4.4.0-1039.45_amd64.debLinux
Linux kernel (USN-3848-1) linux-image-4.4.0-1074-aws_4.4.0-1074.84_amd64.debLinux
Linux kernel (USN-3848-1) linux-image-4.4.0-141-generic_4.4.0-141.167_i386.debLinux
Linux kernel (USN-3848-1) linux-image-4.4.0-141-generic_4.4.0-141.167_amd64.debLinux
Linux kernel (USN-3848-1) linux-image-4.4.0-141-lowlatency_4.4.0-141.167_i386.debLinux
Linux kernel (USN-3848-1) linux-image-4.4.0-141-lowlatency_4.4.0-141.167_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3848-2) linux-image-aws_4.4.0.1037.37_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3848-2) linux-image-4.4.0-1037-aws_4.4.0-1037.40_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3848-2) linux-image-4.4.0-141-generic_4.4.0-141.167~14.04.1_i386.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3848-2) linux-image-4.4.0-141-generic_4.4.0-141.167~14.04.1_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3848-2) linux-image-4.4.0-141-lowlatency_4.4.0-141.167~14.04.1_i386.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-3848-2) linux-image-4.4.0-141-lowlatency_4.4.0-141.167~14.04.1_amd64.debLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-debuginfo-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-debugsource-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-devel-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-extra-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-default-extra-debuginfo-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-devel-4.4.162-94.69.2.noarch.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-macros-4.4.162-94.69.2.noarch.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-source-4.4.162-94.69.2.noarch.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Desktop 12-SP3 ) kernel-syms-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-default-base-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) kernel-default-base-debuginfo-4.4.162-94.69.2.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) lttng-modules-2.7.1-8.6.1.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) lttng-modules-debugsource-2.7.1-8.6.1.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) lttng-modules-kmp-default-2.7.1_k4.4.162_94.69-8.6.1.x86_64.rpmLinux
SUSE-SU-2018:3689-1(SUSE Linux Enterprise Server 12-SP3 ) lttng-modules-kmp-default-debuginfo-2.7.1_k4.4.162_94.69-8.6.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234