7.8

CVE-2018-20669

Exploit
An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kernel memory, resulting in a Denial of Service or privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.13 < 4.14.185
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.129
Linux ≫ Linux Kernel Version >= 4.20 < 5.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Netapp ≫ Hci Management Node Version -
Netapp ≫ Snapprotect Version -
Netapp ≫ Solidfire Version -
Netapp ≫ Cn1610 Firmware Version -
   Netapp ≫ Cn1610 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.427
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://security.netapp.com/advisory/ntap-20190404-0002/
Third Party Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/log/drivers/gpu/drm/i915/i915_gem_execbuffer.c
Vendor Advisory
Release Notes
http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00042.html
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2019/01/23/6
Patch
Third Party Advisory
Exploit
Mailing List
http://www.securityfocus.com/bid/106748
Third Party Advisory
Broken Link
VDB Entry
https://access.redhat.com/security/cve/cve-2018-20669
Third Party Advisory
https://support.f5.com/csp/article/K32059550
Third Party Advisory
https://usn.ubuntu.com/4485-1/
Third Party Advisory