CVE-2018-16658

MEDIUM

Linux kernel <4.18.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940.

References (16)

Core 16
Core References
Mitigation, Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3797-2/
Mitigation, Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3797-1/
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3820-1/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3820-2/
Release Notes, Technical Description x_refsource_misc
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.6
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4308
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3822-2/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3822-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105334
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3820-3/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2043
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2029
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:4154

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Details

CWE
CWE-200
Status published
Products (7)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
debian/debian_linux 8.0
debian/debian_linux 9.0
linux/linux_kernel < 4.18.6
Published Sep 07, 2018
Tracked Since Feb 18, 2026