UBUNTU-CVE-2018-7755
An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use the obtained kernel pointer to discover the location of kernel code and data and bypass kernel security protections such as KASLR.
02 / AFFECTED SOFTWARE
Affected packages
46 explicit affected versions
4 explicit affected versions
6 explicit affected versions
61 explicit affected versions
7 explicit affected versions
12 explicit affected versions
1 explicit affected versions
8 explicit affected versions
12 explicit affected versions
7 explicit affected versions
1 explicit affected versions
15 explicit affected versions
133 explicit affected versions
7 explicit affected versions
23 explicit affected versions
54 explicit affected versions
49 explicit affected versions
13 explicit affected versions
8 explicit affected versions
14 explicit affected versions
15 explicit affected versions
7 explicit affected versions
76 explicit affected versions
51 explicit affected versions
16 explicit affected versions
7 explicit affected versions
35 explicit affected versions
7 explicit affected versions
26 explicit affected versions
6 explicit affected versions
34 explicit affected versions
3 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use the obtained kernel pointer to discover the location of kernel code and data and bypass kernel security protections such as KASLR.
05 / REFERENCES
Further evidence
- https://lkml.org/lkml/2018/3/7/1116
- https://ubuntu.com/security/CVE-2018-7755
- https://ubuntu.com/security/notices/USN-3695-1
- https://ubuntu.com/security/notices/USN-3695-2
- https://ubuntu.com/security/notices/USN-3696-1
- https://ubuntu.com/security/notices/USN-3696-2
- https://ubuntu.com/security/notices/USN-3697-1
- https://ubuntu.com/security/notices/USN-3697-2
- https://ubuntu.com/security/notices/USN-3698-1
- https://ubuntu.com/security/notices/USN-3698-2
- https://www.cve.org/CVERecord?id=CVE-2018-7755