CVE-2018-12931: High severity ubuntu linux vulnerability
A flaw was found in ntfsattrfind in the ntfs.ko filesystem driver in the Linux kernel. This allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service or possibly have unspecified other impact via a crafted ntfs filesystem image. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403 https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2
https://marc.info/?t=152407734400002&r=1&w=2 (a whole thread)
Other sources
ntfsattrfind in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12931?
CVE-2018-12931 is classified as a medium-severity vulnerability due to its potential to cause denial of service or kernel panics.
How do I fix CVE-2018-12931?
To mitigate CVE-2018-12931, you should update to the patched version of the Linux kernel provided by your distribution.
Which software is affected by CVE-2018-12931?
CVE-2018-12931 affects Ubuntu 16.04.4 and Linux Kernel version 4.15.
What are the impacts of exploiting CVE-2018-12931?
Exploitation of CVE-2018-12931 could lead to a stack-based out-of-bounds write, resulting in kernel oops or panic.
Are there any workarounds for CVE-2018-12931?
Currently, the best workaround for CVE-2018-12931 is to avoid using the affected ntfs filesystem until a fix is applied.