VulnerabilityModified
CVE-2018-17972
It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.
MEDIUM 5.5EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- linux/linux kernel · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · debian/debian linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html
- http://www.securityfocus.com/bid/105525Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0512Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0514Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0831
- https://access.redhat.com/errata/RHSA-2019:2473
- https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html
- https://marc.info/?l=linux-fsdevel&m=153806242024956&w=2Patch, Third Party Advisory
- https://support.f5.com/csp/article/K27673650?utm_source=f5support&%3Butm_medium=RSS
- https://usn.ubuntu.com/3821-1/Third Party Advisory
- https://usn.ubuntu.com/3821-2/Third Party Advisory
- https://usn.ubuntu.com/3832-1/Third Party Advisory
- https://usn.ubuntu.com/3835-1/Third Party Advisory
- https://usn.ubuntu.com/3871-1/Third Party Advisory
- https://usn.ubuntu.com/3871-3/Third Party Advisory
- https://usn.ubuntu.com/3871-4/Third Party Advisory
- https://usn.ubuntu.com/3871-5/Third Party Advisory
- https://usn.ubuntu.com/3880-1/Third Party Advisory
- https://usn.ubuntu.com/3880-2/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html
- http://www.securityfocus.com/bid/105525Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0512Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0514Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0831
- https://access.redhat.com/errata/RHSA-2019:2473
- https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.