CVE-2018-16658: Infoleak
An information leak was discovered in the Linux kernel in cdromioctldrivestatus() function in drivers/cdrom/cdrom.c that could be used by local attackers to read kernel memory at certain location.
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8f3fafc9c2f0ece10832c25f7ffcb07c97a32ad4
Other sources
An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdromioctldrivestatus in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 4.18.6
Event History
Frequently Asked Questions
What is CVE-2018-16658?
CVE-2018-16658 is a vulnerability in the Linux kernel that allows local attackers to read kernel memory due to an information leak in the cdrom_ioctl_drive_status function.
What is the severity of CVE-2018-16658?
The severity of CVE-2018-16658 is low.
How can local attackers exploit CVE-2018-16658?
Local attackers can exploit CVE-2018-16658 by using an information leak in cdrom_ioctl_drive_status to read kernel memory.
Which versions of the Linux kernel are affected by CVE-2018-16658?
Versions before 4.18.6 of the Linux kernel are affected by CVE-2018-16658.
Is there a fix for CVE-2018-16658?
Yes, updating the Linux kernel to version 4.18.6 or later can fix CVE-2018-16658.