UBUNTU-CVE-2018-16658
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-16658
UBUNTU-CVE-2018-16658
Summary:
Details: An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940.
References: https://ubuntu.com/security/CVE-2018-16658, http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8f3fafc9c2f0ece10832c25f7ffcb07c97a32ad4, https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.6, https://ubuntu.com/security/notices/USN-3797-1, https://ubuntu.com/security/notices/USN-3797-2, https://ubuntu.com/security/notices/USN-3820-1, https://ubuntu.com/security/notices/USN-3820-2, https://ubuntu.com/security/notices/USN-3820-3, https://ubuntu.com/security/notices/USN-3822-1, https://ubuntu.com/security/notices/USN-3822-2, https://www.cve.org/CVERecord?id=CVE-2018-16658
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
