7.1

CVE-2018-10880

Exploit
Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data(). An attacker could use this to cause a system crash and a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Linux ≫ Linux Kernel Version < 4.17.6
Redhat ≫ Enterprise Linux Version 7.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.91% 0.852
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
RedHat 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://access.redhat.com/errata/RHSA-2018:2948
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/3821-1/
Third Party Advisory
https://usn.ubuntu.com/3821-2/
Third Party Advisory
http://www.securityfocus.com/bid/106503
Third Party Advisory
VDB Entry
https://usn.ubuntu.com/3871-1/
Third Party Advisory
https://usn.ubuntu.com/3871-3/
Third Party Advisory
https://usn.ubuntu.com/3871-4/
Third Party Advisory
https://usn.ubuntu.com/3871-5/
Third Party Advisory
http://patchwork.ozlabs.org/patch/930639/
Patch
Third Party Advisory
http://www.securityfocus.com/bid/104907
https://bugzilla.kernel.org/show_bug.cgi?id=200005
Patch
Vendor Advisory
Exploit
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10880
Patch
Third Party Advisory
Exploit
Issue Tracking
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8cdb5240ec5928b20490a2bb34cb87e9a5f40226
Patch
Vendor Advisory