CVE-2018-14633: Buffer Overflow
A security flaw was found in the chapservercomputemd5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. An attack requires the ISCSI target to be enabled on the victim host. Depending on how the target's code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead to a system crash and thus to a denial-of-service or possibly to a non-authorized access to data exported by an ISCSI target. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is highly unlikely.
References:
https://seclists.org/oss-sec/2018/q3/270
Upstream patches:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1816494330a8
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8c39e2699f8a
Other sources
A security flaw was found in the chapservercomputemd5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depending on how the target's code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead to a system crash and thus to a denial-of-service or possibly to a non-authorized access to data exported by an iSCSI target. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is highly unlikely. Kernel versions 4.18.x, 4.14.x and 3.10.x are believed to be vulnerable.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1
Event History
Frequently Asked Questions
What is CVE-2018-14633?
CVE-2018-14633 is a security flaw found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel.
How does CVE-2018-14633 affect Linux systems?
CVE-2018-14633 can allow an unauthenticated remote attacker to cause a stack buffer overflow and potentially execute arbitrary code.
Which Linux distributions are affected by CVE-2018-14633?
Linux distributions with the Linux kernel version up to 4.19~ are affected by CVE-2018-14633.
What is the severity of CVE-2018-14633?
CVE-2018-14633 has a severity rating of medium.
How can I fix CVE-2018-14633?
To fix CVE-2018-14633, update the Linux kernel to version 4.19~ or later.