CVE-2018-8822

Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the kernel or execute code.
References
Link Resource
http://www.openwall.com/lists/oss-security/2022/12/27/3 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/103476 Broken Link Third Party Advisory VDB Entry
https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html Mailing List Third Party Advisory
https://usn.ubuntu.com/3653-1/ Third Party Advisory
https://usn.ubuntu.com/3653-2/ Third Party Advisory
https://usn.ubuntu.com/3654-1/ Third Party Advisory
https://usn.ubuntu.com/3654-2/ Third Party Advisory
https://usn.ubuntu.com/3655-1/ Third Party Advisory
https://usn.ubuntu.com/3655-2/ Third Party Advisory
https://usn.ubuntu.com/3656-1/ Third Party Advisory
https://usn.ubuntu.com/3657-1/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4187 Third Party Advisory
https://www.debian.org/security/2018/dsa-4188 Third Party Advisory
https://www.mail-archive.com/netdev%40vger.kernel.org/msg223373.html Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.16:rc:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.16:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.16:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.16:rc6:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

28 Mar 2024, 16:08

Type Values Removed Values Added
References () https://www.mail-archive.com/netdev%40vger.kernel.org/msg223373.html - () https://www.mail-archive.com/netdev%40vger.kernel.org/msg223373.html - Patch, Third Party Advisory

07 Nov 2023, 03:01

Type Values Removed Values Added
References
  • {'url': 'https://www.mail-archive.com/netdev@vger.kernel.org/msg223373.html', 'name': 'https://www.mail-archive.com/netdev@vger.kernel.org/msg223373.html', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • () https://www.mail-archive.com/netdev%40vger.kernel.org/msg223373.html -

03 Mar 2023, 15:10

Type Values Removed Values Added
References (MLIST) http://www.openwall.com/lists/oss-security/2022/12/27/3 - (MLIST) http://www.openwall.com/lists/oss-security/2022/12/27/3 - Mailing List, Third Party Advisory
References (BID) http://www.securityfocus.com/bid/103476 - Third Party Advisory, VDB Entry (BID) http://www.securityfocus.com/bid/103476 - Broken Link, Third Party Advisory, VDB Entry

27 Dec 2022, 13:15

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/12/27/3 -

Information

Published : 2018-03-20 17:29

Updated : 2024-03-28 16:08


NVD link : CVE-2018-8822

Mitre link : CVE-2018-8822

CVE.ORG link : CVE-2018-8822


JSON object : View

Products Affected

debian

  • debian_linux

canonical

  • ubuntu_linux

linux

  • linux_kernel
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer