Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1558697 - (CVE-2018-8822) CVE-2018-8822 kernel: Memory corruption in ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c
CVE-2018-8822 kernel: Memory corruption in ncp_read_kernel function in fs/ncp...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180320,repor...
: Security
Depends On: 1558698
Blocks: 1558699
  Show dependency treegraph
 
Reported: 2018-03-20 16:13 EDT by Pedro Sampaio
Modified: 2018-03-26 14:47 EDT (History)
46 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Incorrect buffer length handling was found in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel, which could be exploited by malicious NCPFS servers to crash the kernel or possibly execute an arbitrary code.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-03-22 12:30:23 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Pedro Sampaio 2018-03-20 16:13:23 EDT
Incorrect buffer length handling was found in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel, which could be exploited by malicious NCPFS servers to crash the kernel or possibly execute an arbitrary code.

References:

https://www.mail-archive.com/netdev@vger.kernel.org/msg223373.html

A suggested fix:

https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/staging.git/commit/?id=4c41aa24baa4ed338241d05494f2c595c885af8f
Comment 1 Pedro Sampaio 2018-03-20 16:14:34 EDT
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1558698]
Comment 2 Justin M. Forbes 2018-03-20 17:21:47 EDT
NCPFS is not enabled in Fedora any longer it is scheduled for removal from the upstream kernel.
Comment 5 Vladis Dronov 2018-03-22 12:30:23 EDT
Notes:

See upstream commita 1bb8155080c6 and 5d8515bc2321:

      The networking IPX and the ncpfs filesystem are moved into the staging
      tree, as they are on their way out of the kernel due to lack of use
      anymore.

Note You need to log in before you can comment on or make changes to this bug.