CVE-2018-1000026: Input Validation
Improper validation in the bnx2x network card driver of the Linux kernel version 4.15 can allow for denial of service (DoS) attacks via a packet with a gsosize larger than ~9700 bytes. Untrusted guest VMs can exploit this vulnerability in the host machine, causing a crash in the network card.
References:
https://patchwork.ozlabs.org/patch/859410/
https://marc.info/?t=151606867000005&r=1&w=2
http://lists.openwall.net/netdev/2018/01/16/40
http://lists.openwall.net/netdev/2018/01/18/96
Upstream commits:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8914a595110a6eca69a5e275b323f5d09e18f4f9
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2b16f048729bf35e6c28a40cbfad07239f9dcd90
Other sources
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000026?
CVE-2018-1000026 has a severity rating that indicates it can lead to denial of service (DoS) attacks.
How do I fix CVE-2018-1000026?
To fix CVE-2018-1000026, you should upgrade the Linux kernel to version 5.10.223-1 or later.
Which Linux distributions are affected by CVE-2018-1000026?
CVE-2018-1000026 affects certain versions of Red Hat Enterprise Linux, Ubuntu Linux, and Debian Linux.
Can CVE-2018-1000026 be exploited by untrusted guest VMs?
Yes, CVE-2018-1000026 can be exploited by untrusted guest VMs to crash the network card on the host machine.
What specific kernel version ranges are impacted by CVE-2018-1000026?
CVE-2018-1000026 impacts Linux kernel versions between 4.4.181 and 4.16, as well as several specific Ubuntu and Red Hat versions.