CVE-2018-12930: High severity linux kernel vulnerability
A flaw was found in ntfsendbufferasyncread in the ntfs.ko filesystem driver in the Linux kernel. This allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service or possibly have unspecified other impact via a crafted ntfs filesystem. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403
https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2
https://marc.info/?t=152407734400002&r=1&w=2 (a whole thread)
Other sources
ntfsendbufferasyncread in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12930?
CVE-2018-12930 is considered to have a high severity due to the potential for denial of service and other unspecified impacts.
How do I fix CVE-2018-12930?
To fix CVE-2018-12930, it is recommended to update the Linux kernel to a version beyond 4.15.0, as later versions contain patches addressing this vulnerability.
What systems are affected by CVE-2018-12930?
CVE-2018-12930 affects the Linux kernel version 4.15.0 and Ubuntu Linux version 16.04.4.
What type of vulnerability is CVE-2018-12930?
CVE-2018-12930 is a stack-based out-of-bounds write vulnerability that can be exploited through a crafted ntfs filesystem.
Can CVE-2018-12930 lead to remote exploits?
While CVE-2018-12930 primarily causes a denial of service, it could potentially be used for further exploitation under certain conditions.