Red Hat Bugzilla – Bug 1640596
CVE-2018-18445 kernel: Faulty computation of numberic bounds in the BPF verifier
Last modified: 2018-10-24 14:23:12 EDT
A security flaw was found in the Linux kernel in the adjust_scalar_min_max_vals() function in kernel/bpf/verifier.c. A faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because this function mishandles 32-bit right shifts. This can lead to a system panic and a denial of service or other unspecified impact. References: https://bugs.chromium.org/p/project-zero/issues/detail?id=1686 https://seclists.org/oss-sec/2018/q4/69 An upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b799207e1e1816b09e7a5920fbb2d5fcf6edd681