7.8

CVE-2018-16276

An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.37 < 3.16.58
Linux ≫ Linux Kernel Version >= 3.17 < 3.18.116
Linux ≫ Linux Kernel Version >= 3.19 < 4.4.141
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.113
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.56
Linux ≫ Linux Kernel Version >= 4.15 < 4.17.7
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.349
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://usn.ubuntu.com/3849-1/
Third Party Advisory
https://usn.ubuntu.com/3849-2/
Third Party Advisory
https://usn.ubuntu.com/3776-1/
Third Party Advisory
https://usn.ubuntu.com/3776-2/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2018/dsa-4308
Third Party Advisory
https://usn.ubuntu.com/3847-1/
Third Party Advisory
https://usn.ubuntu.com/3847-2/
Third Party Advisory
https://usn.ubuntu.com/3847-3/
Third Party Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f1e255d60ae66a9f672ff9a207ee6cd8e33d2679
Patch
Vendor Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1106095
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=1115593
Issue Tracking
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.7
Vendor Advisory
https://github.com/torvalds/linux/commit/f1e255d60ae66a9f672ff9a207ee6cd8e33d2679
Patch
Third Party Advisory