Bug 1610555 (CVE-2018-15471)
Summary: | CVE-2018-15471 kernel: net: xen: Linux netback driver OOB access in hash handling (XSA-270) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Laura Pardo <lpardo> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | ailan, airlied, aquini, bhu, blc, bskeggs, dhoward, drjones, esammons, ewk, fhrbata, hdegoede, hkrzesin, hwkernel-mgr, iboverma, ichavero, imammedo, itamar, jarodwilson, jforbes, jglisse, jkacur, john.j5live, jonathan, josef, jross, jstancek, jwboyer, kernel-maint, kernel-mgr, knoel, labbott, lgoncalv, linville, lwang, matt, m.a.young, mchehab, mcressma, mjg59, mlangsdo, mrezanin, nmurray, pbonzini, plougher, rkrcmar, robinlee.sysu, rt-maint, rvrbovsk, security-response-team, skozina, steved, vdronov, vkuznets, williams, wmealing, xen-maint |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A flaw in the netback module allowed frontends to control mapping of requests to request queues. An attacker can change this mapping by requesting invalid mapping requests allowing the (usually privileged) backend to access out-of-bounds memory access for reading and writing.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2018-08-30 09:06:26 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1618413, 1618414 | ||
Bug Blocks: | 1610556 |
Description
Laura Pardo
2018-07-31 22:05:59 UTC
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1618414] Created xen tracking bugs for this issue: Affects: fedora-all [bug 1618413] |