First published: Fri Jun 29 2018(Updated: )
A flaw was found in Linux kernel ext4 filesystem. A local user can cause an out-of-bound write and so a denial of service or possibly unspecified other impact by mounting and operating a crafted ext4 filesystem image. References: <a href="https://bugzilla.kernel.org/show_bug.cgi?id=199865">https://bugzilla.kernel.org/show_bug.cgi?id=199865</a> Upstream patches: <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=819b23f1c501b17b9694325471789e6b5cc2d0d2">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=819b23f1c501b17b9694325471789e6b5cc2d0d2</a> <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=77260807d1170a8cf35dbb06e07461a655f67eee">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=77260807d1170a8cf35dbb06e07461a655f67eee</a>
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Linux Kernel | <3.16.58 | |
Linux Kernel | >=3.17<3.18.124 | |
Linux Kernel | >=3.19<4.4.140 | |
Linux Kernel | >=4.5<4.9.112 | |
Linux Kernel | >=4.10<4.14.55 | |
Linux Kernel | >=4.15<4.17.6 | |
Debian Linux | =8.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.133-1 6.12.21-1 6.12.22-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10878 has a severity rating that may allow for denial of service or potentially other impacts due to an out-of-bounds write flaw.
To fix CVE-2018-10878, update the Linux kernel to a patched version that addresses the flaw.
CVE-2018-10878 affects various Linux kernel versions including those in Ubuntu 14.04, 16.04, 18.04, and several versions of Debian and Red Hat Enterprise Linux.
CVE-2018-10878 requires local user access, meaning it cannot be exploited remotely without local access to the system.
CVE-2018-10878 is associated with an attack that can lead to denial of service through manipulation of a crafted ext4 filesystem image.