CVE-2018-20836: Race Condition
A flaw was found in the Linux kernel’s implementation of the SAS expander subsystem, where a race condition exists in the smptasktimedout() and smptaskdone() in drivers/scsi/libsas/sasexpander.c. An attacker could abuse this flaw to corrupt memory and escalate privileges.
Other sources
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smptasktimedout() and smptaskdone() in drivers/scsi/libsas/sasexpander.c, leading to a use-after-free.
An issue was discovered in the Linux kernels implementation of SAS expander functionality. A race condition in smptasktimedout() and smptaskdone() in drivers/scsi/libsas/sasexpander.c could allow an attacker who is able to issue SAS commands to create a conditon where it could be manipulated into a use-after-free scenario allowing for memory corruption or possibly escalate privileges.
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b90cd6f2b905905fb42671009dc0e27c310a16ae https://github.com/torvalds/linux/commit/b90cd6f2b905905fb42671009dc0e27c310a16ae
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.rt56.1131.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.65.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.43.1.el7 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch b90cd6f2b905905fb42671009dc0e27c310a16ae
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-20836?
CVE-2018-20836 is classified as a high severity vulnerability due to its potential for privilege escalation and memory corruption.
How do I fix CVE-2018-20836?
To fix CVE-2018-20836, users should update to the latest kernel version that addresses this vulnerability according to their distribution.
Which systems are affected by CVE-2018-20836?
CVE-2018-20836 affects various versions of the Linux kernel up to version 4.19.42 as well as specific Red Hat kernel packages.
What types of attacks can exploit CVE-2018-20836?
An attacker can exploit CVE-2018-20836 to potentially cause memory corruption and escalate privileges on the affected systems.
Which distributions provide patches for CVE-2018-20836?
Patches for CVE-2018-20836 are available from major distributions such as Red Hat, Debian, and Ubuntu.