CVE-2018-1000204

Published: 26 June 2018

** DISPUTED ** Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://github.com/torvalds/linux/commit/a45b599ad808c3c982fdcdc12b0b8611c2f92824 already. The problem has limited scope, as users don't usually have permissions to access SCSI devices. On the other hand, e.g. the Nero user manual suggests doing `chmod o+r+w /dev/sg*` to make the devices accessible. NOTE: third parties dispute the relevance of this report, noting that the requirement for an attacker to have both the CAP_SYS_ADMIN and CAP_SYS_RAWIO capabilities makes it "virtually impossible to exploit."

From the Ubuntu security team

It was discovered that an information leak existed in the generic SCSI driver in the Linux kernel. A local attacker could use this to expose sensitive information (kernel memory).

Priority

Negligible

CVSS 3 base score: 5.3

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-33.36)
Patches:
Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed by a45b599ad808c3c982fdcdc12b0b8611c2f92824
linux-aws
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1020.20)
linux-azure
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1022.23)
linux-azure-edge
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.18.0-1003.3~18.04.1)
linux-euclid
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-flo
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-gcp
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1018.19)
linux-gke
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-goldfish
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-grouper
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable

linux-hwe-edge
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.18.0-11.12~18.04.1)
linux-kvm
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1020.20)
linux-lts-trusty
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-utopic
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-vivid
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-wily
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-xenial
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-maguro
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-mako
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-manta
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-oem
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1017.20)
linux-raspi2
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1021.23)
linux-snapdragon
Launchpad, Ubuntu, Debian
Upstream
Released (4.17~rc7)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable