CVE-2018-10878
Published: July 26, 2018Last modified: October 6, 2023
Description
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 7.8 | 
| Attack Vector | LOCAL | 
| Attack complexity | LOW | 
| Privileges required | LOW | 
| User interaction | NONE | 
| Scope | UNCHANGED | 
| Confidentiality | HIGH | 
| Integrity impact | HIGH | 
| Availability impact | HIGH | 
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Not affected (6.1.50-r0) | 
| Stream | linux-lts | Not affected (6.1.50-r0) | 
References
- http://patchwork.ozlabs.org/patch/929237/
 - http://patchwork.ozlabs.org/patch/929238/
 - https://access.redhat.com/errata/RHSA-2018:2948
 - https://access.redhat.com/errata/RHSA-2018:3083
 - https://access.redhat.com/errata/RHSA-2018:3096
 - https://bugzilla.kernel.org/show_bug.cgi?id=199865
 - https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10878
 - https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=77260807d1170a8cf35dbb06e07461a655f67eee
 - https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=819b23f1c501b17b9694325471789e6b5cc2d0d2
 - https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html
 - https://usn.ubuntu.com/3753-1/
 - https://usn.ubuntu.com/3753-2/
 - https://usn.ubuntu.com/3871-1/
 - https://usn.ubuntu.com/3871-3/
 - https://usn.ubuntu.com/3871-4/
 - https://usn.ubuntu.com/3871-5/