UBUNTU-CVE-2018-14625
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
02 / AFFECTED SOFTWARE
Affected packages
6 explicit affected versions
2 explicit affected versions
29 explicit affected versions
25 explicit affected versions
45 explicit affected versions
1 explicit affected versions
23 explicit affected versions
18 explicit affected versions
20 explicit affected versions
17 explicit affected versions
12 explicit affected versions
1 explicit affected versions
18 explicit affected versions
15 explicit affected versions
1 explicit affected versions
20 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
05 / REFERENCES
Further evidence
- https://lore.kernel.org/lkml/[email protected]/
- https://lore.kernel.org/lkml/?q=%22syzbot%2Bbd391451452fb0b93039%40syzkaller.appspotmail.com%22
- https://syzkaller.appspot.com/bug?extid=bd391451452fb0b93039
- https://ubuntu.com/security/CVE-2018-14625
- https://ubuntu.com/security/notices/USN-3871-1
- https://ubuntu.com/security/notices/USN-3871-3
- https://ubuntu.com/security/notices/USN-3871-4
- https://ubuntu.com/security/notices/USN-3871-5
- https://ubuntu.com/security/notices/USN-3872-1
- https://ubuntu.com/security/notices/USN-3878-1
- https://ubuntu.com/security/notices/USN-3878-2
- https://www.cve.org/CVERecord?id=CVE-2018-14625