Bug 1541240 (CVE-2018-6412) - CVE-2018-6412 kernel: Incorrect integer signedness in sbuslibc:sbusfb_ioctl_helper() allows for information leakage
Summary: CVE-2018-6412 kernel: Incorrect integer signedness in sbuslibc:sbusfb_ioctl_h...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-6412
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1541241
Blocks: 1541243
TreeView+ depends on / blocked
 
Reported: 2018-02-02 04:34 UTC by Sam Fowler
Modified: 2021-02-17 00:52 UTC (History)
45 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel, up to and including 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.
Clone Of:
Environment:
Last Closed: 2018-02-14 16:12:12 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-02-02 04:34:20 UTC
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel up to and including 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.

External References:
https://nvd.nist.gov/vuln/detail/CVE-2018-6412

Upstream Patch:
https://marc.info/?l=linux-fbdev&m=151734425901499

Comment 1 Sam Fowler 2018-02-02 04:35:11 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1541241]

Comment 2 Justin M. Forbes 2018-02-02 14:28:51 UTC
Sparc is not a supported architecture for Fedora, so this does not impact Fedora users

Comment 5 Vladis Dronov 2018-02-14 16:12:12 UTC
Statement:

This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7, its real-time kernel, Red Hat Enterprise MRG 2, Red Hat Enterprise Linux 7 for ARM 64 and Red Hat Enterprise Linux 7 for Power 9 LE, as the code with the flaw is not built and is not shipped with the products listed.


Note You need to log in before you can comment on or make changes to this bug.