Bug 1758671 (CVE-2017-18595) - CVE-2017-18595 kernel: double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c
Summary: CVE-2017-18595 kernel: double free may be caused by the function allocate_tra...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2017-18595
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1803011 1803019 1759138 1802950 1802951 1802952 1802953 1802954 1802955 1802957 1802958 1802959 1802960 1802961 1802962 1802963 1802964 1802965 1802966 1803010 1803012 1803018
Blocks: 1758672
TreeView+ depends on / blocked
 
Reported: 2019-10-04 19:50 UTC by Guilherme de Almeida Suckevicz
Modified: 2020-06-17 12:24 UTC (History)
53 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the allocate_trace_buffer in kernel/trace/trace.c in the debug subsystem, when failure to allocate a dynamic percpu area, a resource cleanup is called. The pointer (buf->buffer) still holds the address and is not set to NULL, which can cause a use-after-free problem, leading to a dangling pointer issue.
Clone Of:
Environment:
Last Closed: 2020-05-12 16:32:00 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2020:2233 None None None 2020-05-20 12:27:39 UTC
Red Hat Product Errata RHSA-2020:2082 None None None 2020-05-12 18:38:16 UTC
Red Hat Product Errata RHSA-2020:2085 None None None 2020-05-12 18:38:40 UTC
Red Hat Product Errata RHSA-2020:2104 None None None 2020-05-12 15:12:24 UTC
Red Hat Product Errata RHSA-2020:2214 None None None 2020-05-19 14:41:32 UTC
Red Hat Product Errata RHSA-2020:2242 None None None 2020-05-20 17:35:40 UTC
Red Hat Product Errata RHSA-2020:2277 None None None 2020-05-26 09:39:56 UTC
Red Hat Product Errata RHSA-2020:2285 None None None 2020-05-26 08:48:33 UTC
Red Hat Product Errata RHSA-2020:2289 None None None 2020-05-26 11:17:15 UTC
Red Hat Product Errata RHSA-2020:2522 None None None 2020-06-11 02:10:20 UTC

Description Guilherme de Almeida Suckevicz 2019-10-04 19:50:19 UTC
An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c.

Reference:
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.11
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4397f04575c44e1440ec2e49b6302785c95fd2f8

Comment 1 Guilherme de Almeida Suckevicz 2019-10-07 13:13:57 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1759138]

Comment 2 Justin M. Forbes 2019-10-07 14:26:18 UTC
This was fixed for fedora in the 4.14.11 stable update, and never impacted any of the still currently supported versions of Fedora.

Comment 6 Rohit Keshri 2020-02-14 08:56:27 UTC
Mitigation:

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Comment 17 errata-xmlrpc 2020-05-12 15:12:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:2104 https://access.redhat.com/errata/RHSA-2020:2104

Comment 18 Product Security DevOps Team 2020-05-12 16:32:00 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2017-18595

Comment 19 errata-xmlrpc 2020-05-12 18:38:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:2082 https://access.redhat.com/errata/RHSA-2020:2082

Comment 20 errata-xmlrpc 2020-05-12 18:38:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:2085 https://access.redhat.com/errata/RHSA-2020:2085

Comment 21 errata-xmlrpc 2020-05-19 14:41:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.4 Advanced Update Support
  Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 7.4 Telco Extended Update Support

Via RHSA-2020:2214 https://access.redhat.com/errata/RHSA-2020:2214

Comment 22 errata-xmlrpc 2020-05-20 17:35:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise MRG 2

Via RHSA-2020:2242 https://access.redhat.com/errata/RHSA-2020:2242

Comment 23 errata-xmlrpc 2020-05-26 08:48:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.2 Advanced Update Support

Via RHSA-2020:2285 https://access.redhat.com/errata/RHSA-2020:2285

Comment 24 errata-xmlrpc 2020-05-26 09:39:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.3 Advanced Update Support
  Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
  Red Hat Enterprise Linux 7.3 Telco Extended Update Support

Via RHSA-2020:2277 https://access.redhat.com/errata/RHSA-2020:2277

Comment 25 errata-xmlrpc 2020-05-26 11:17:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.6 Extended Update Support

Via RHSA-2020:2289 https://access.redhat.com/errata/RHSA-2020:2289

Comment 27 errata-xmlrpc 2020-06-11 02:10:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.7 Extended Update Support

Via RHSA-2020:2522 https://access.redhat.com/errata/RHSA-2020:2522


Note You need to log in before you can comment on or make changes to this bug.