CVE-2018-18445: High severity Linux Linux kernel vulnerability
A security flaw was found in the Linux kernel in the adjustscalarminmaxvals() function in kernel/bpf/verifier.c. A faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because this function mishandles 32-bit right shifts. A local unprivileged user cannot leverage this flaw, but as a privileged user ("root") this can lead to a system panic and a denial of service or other unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://bugs.chromium.org/p/project-zero/issues/detail?id=1686
https://seclists.org/oss-sec/2018/q4/69
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b799207e1e1816b09e7a5920fbb2d5fcf6edd681
Other sources
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjustscalarminmaxvals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 4.18.13
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18445?
CVE-2018-18445 has been rated as a medium severity vulnerability due to its potential for causing out-of-bounds memory access.
How do I fix CVE-2018-18445?
To fix CVE-2018-18445, you should update your Linux kernel to the recommended versions provided by your distribution, such as those above 4.14.75 or 4.18.13.
Which Linux distributions are affected by CVE-2018-18445?
CVE-2018-18445 affects various versions of the Linux kernel, including those used in Ubuntu 14.04, 16.04, 18.04, 18.10, and Red Hat Enterprise Linux version 7.0 and 7.6.
Can CVE-2018-18445 be exploited remotely?
CVE-2018-18445 requires local access to the system to exploit the vulnerability, limiting its risk to local unprivileged users.
What versions of the Linux kernel have patched CVE-2018-18445?
The vulnerability CVE-2018-18445 has been patched in kernel versions 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.11-1, and 6.12.12-1.