6.1

CVE-2018-16658

An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 4.18.6
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.417
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 1.8 4.2
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:N/A:P
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://usn.ubuntu.com/3822-1/
Third Party Advisory
https://usn.ubuntu.com/3822-2/
Third Party Advisory
https://usn.ubuntu.com/3820-1/
Third Party Advisory
https://usn.ubuntu.com/3820-2/
Third Party Advisory
https://usn.ubuntu.com/3820-3/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4154
https://access.redhat.com/errata/RHSA-2019:2029
https://access.redhat.com/errata/RHSA-2019:2043
https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2018/dsa-4308
Third Party Advisory
https://usn.ubuntu.com/3797-1/
Third Party Advisory
Mitigation
https://usn.ubuntu.com/3797-2/
Third Party Advisory
Mitigation
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8f3fafc9c2f0ece10832c25f7ffcb07c97a32ad4
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/105334
Third Party Advisory
VDB Entry
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.6
Release Notes
Technical Description
https://github.com/torvalds/linux/commit/8f3fafc9c2f0ece10832c25f7ffcb07c97a32ad4
Patch