CVE-2018-14625
Last modified
CVE-2018-14625 is a vulnerability of currently unknown severity. A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | All versions |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 18.10 |
| Debian | Debian Linux | 8.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14625Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.htmlMailing List, Third Party Advisory
- https://syzkaller.appspot.com/bug?extid=bd391451452fb0b93039Third Party Advisory
- https://usn.ubuntu.com/3871-1/Third Party Advisory
- https://usn.ubuntu.com/3871-3/Third Party Advisory
- https://usn.ubuntu.com/3871-4/Third Party Advisory
- https://usn.ubuntu.com/3871-5/Third Party Advisory
- https://usn.ubuntu.com/3872-1/Third Party Advisory
- https://usn.ubuntu.com/3878-1/Third Party Advisory
- https://usn.ubuntu.com/3878-2/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14625Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.htmlMailing List, Third Party Advisory
- https://syzkaller.appspot.com/bug?extid=bd391451452fb0b93039Third Party Advisory
- https://usn.ubuntu.com/3871-1/Third Party Advisory
- https://usn.ubuntu.com/3871-3/Third Party Advisory
- https://usn.ubuntu.com/3871-4/Third Party Advisory
- https://usn.ubuntu.com/3871-5/Third Party Advisory
- https://usn.ubuntu.com/3872-1/Third Party Advisory
- https://usn.ubuntu.com/3878-1/Third Party Advisory
- https://usn.ubuntu.com/3878-2/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14625?
How severe is CVE-2018-14625?
How do I fix CVE-2018-14625?
Are you affected by CVE-2018-14625?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
