CVE-2018-19854
04.12.2018, 16:29
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 𝑥 < 4.19.3 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| linux |
| ||||||||
| linux-aws |
| ||||||||
| linux-aws-hwe |
| ||||||||
| linux-azure |
| ||||||||
| linux-azure-edge |
| ||||||||
| linux-euclid |
| ||||||||
| linux-flo |
| ||||||||
| linux-gcp |
| ||||||||
| linux-gcp-edge |
| ||||||||
| linux-gke |
| ||||||||
| linux-goldfish |
| ||||||||
| linux-grouper |
| ||||||||
| linux-hwe |
| ||||||||
| linux-hwe-edge |
| ||||||||
| linux-kvm |
| ||||||||
| linux-lts-trusty |
| ||||||||
| linux-lts-utopic |
| ||||||||
| linux-lts-vivid |
| ||||||||
| linux-lts-wily |
| ||||||||
| linux-lts-xenial |
| ||||||||
| linux-maguro |
| ||||||||
| linux-mako |
| ||||||||
| linux-manta |
| ||||||||
| linux-oem |
| ||||||||
| linux-oracle |
| ||||||||
| linux-raspi2 |
| ||||||||
| linux-snapdragon |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| kernel-azure |
| ||||||||||||||||
| kernel-azure-base |
| ||||||||||||||||
| kernel-default |
| ||||||||||||||||
| kernel-default-base |
| ||||||||||||||||
| kernel-default-man |
| ||||||||||||||||
| kernel-docs |
| ||||||||||||||||
| kernel-macros |
| ||||||||||||||||
| kernel-obs-build |
| ||||||||||||||||
| kernel-source |
| ||||||||||||||||
| kernel-source-azure |
| ||||||||||||||||
| kernel-syms |
| ||||||||||||||||
| kernel-syms-azure |
| ||||||||||||||||
| kernel-vanilla-base |
| ||||||||||||||||
| kernel-zfcpdump |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| bpftool |
| ||
| kernel |
| ||
| kernel-abi-whitelists |
| ||
| kernel-core |
| ||
| kernel-debug |
| ||
| kernel-debug-core |
| ||
| kernel-debug-devel |
| ||
| kernel-debug-modules |
| ||
| kernel-debug-modules-extra |
| ||
| kernel-devel |
| ||
| kernel-doc |
| ||
| kernel-modules |
| ||
| kernel-modules-extra |
| ||
| kernel-rt |
| ||
| kernel-rt-core |
| ||
| kernel-rt-debug |
| ||
| kernel-rt-debug-core |
| ||
| kernel-rt-debug-devel |
| ||
| kernel-rt-debug-kvm |
| ||
| kernel-rt-debug-modules |
| ||
| kernel-rt-debug-modules-extra |
| ||
| kernel-rt-devel |
| ||
| kernel-rt-kvm |
| ||
| kernel-rt-modules |
| ||
| kernel-rt-modules-extra |
| ||
| kernel-tools |
| ||
| kernel-tools-libs |
| ||
| kernel-tools-libs-devel |
| ||
| kernel-zfcpdump |
| ||
| kernel-zfcpdump-core |
| ||
| kernel-zfcpdump-devel |
| ||
| kernel-zfcpdump-modules |
| ||
| kernel-zfcpdump-modules-extra |
| ||
| perf |
| ||
| python3-perf |
|
Common Weakness Enumeration
References