UBUNTU-CVE-2018-12233
In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability can be triggered by an unprivileged user with the ability to create files and execute programs. A kmalloc call is incorrect, leading to slab-out-of-bounds in jfs_xattr.
02 / AFFECTED SOFTWARE
Affected packages
136 explicit affected versions
17 explicit affected versions
57 explicit affected versions
79 explicit affected versions
38 explicit affected versions
20 explicit affected versions
18 explicit affected versions
38 explicit affected versions
17 explicit affected versions
51 explicit affected versions
49 explicit affected versions
16 explicit affected versions
11 explicit affected versions
11 explicit affected versions
10 explicit affected versions
11 explicit affected versions
8 explicit affected versions
12 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
7 explicit affected versions
7 explicit affected versions
8 explicit affected versions
7 explicit affected versions
1 explicit affected versions
61 explicit affected versions
3 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability can be triggered by an unprivileged user with the ability to create files and execute programs. A kmalloc call is incorrect, leading to slab-out-of-bounds in jfs_xattr.
05 / REFERENCES
Further evidence
- https://lkml.org/lkml/2018/6/2/2
- https://marc.info/?l=linux-kernel&m=152814391530549&w=2
- https://ubuntu.com/security/CVE-2018-12233
- https://ubuntu.com/security/notices/USN-3752-1
- https://ubuntu.com/security/notices/USN-3752-2
- https://ubuntu.com/security/notices/USN-3752-3
- https://ubuntu.com/security/notices/USN-3753-1
- https://ubuntu.com/security/notices/USN-3753-2
- https://ubuntu.com/security/notices/USN-3754-1
- https://www.cve.org/CVERecord?id=CVE-2018-12233