Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 1533909 (CVE-2018-5344) - CVE-2018-5344 kernel: drivers/block/loop.c mishandles lo_release serialization allowing denial-of-service
Summary: CVE-2018-5344 kernel: drivers/block/loop.c mishandles lo_release serializatio...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-5344
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1533910 1533911 1541228 1541229 1541230 1541231 1541232 1740295 1740296 1740297
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-01-12 14:03 UTC by Adam Mariš
Modified: 2021-02-17 00:59 UTC (History)
44 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2019-06-08 03:36:58 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2948 0 None None None 2018-10-30 08:57:23 UTC
Red Hat Product Errata RHSA-2018:3083 0 None None None 2018-10-30 07:31:15 UTC
Red Hat Product Errata RHSA-2018:3096 0 None None None 2018-10-30 07:37:23 UTC

Description Adam Mariš 2018-01-12 14:03:33 UTC
A flaw was found in the Linux kernels handling of loopback devices where it mishandles the release (lo_release function) where an attacker who has permissions to setup loopback disks.

This may allow an attacker to cause a denial of service (__lock_acquire use-after-free) or possibly have unspecified other impact.

Upstream patch:

https://github.com/torvalds/linux/commit/ae6650163c66a7eff1acd6eb8b0f752dcfa8eba5

Comment 1 Adam Mariš 2018-01-12 14:05:42 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1533911]

Comment 8 Eric Christensen 2018-02-02 16:17:30 UTC
Statement:

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6.

This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2.

Future Linux kernel updates for the respective releases may address this issue.

Comment 9 errata-xmlrpc 2018-10-30 07:30:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:3083 https://access.redhat.com/errata/RHSA-2018:3083

Comment 10 errata-xmlrpc 2018-10-30 07:37:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:3096 https://access.redhat.com/errata/RHSA-2018:3096

Comment 11 errata-xmlrpc 2018-10-30 08:57:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:2948 https://access.redhat.com/errata/RHSA-2018:2948


Note You need to log in before you can comment on or make changes to this bug.