An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random. For example, a local user can cause a denial of service (signed integer overflow) via crafted mmap, futex, timer_create, and timer_settime system calls.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1715-1 linux-4.9 security update
Debian DLA Debian DLA DLA-1731-1 linux security update
Debian DLA Debian DLA DLA-1731-2 linux regression update
EUVD EUVD EUVD-2018-4849 An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, which are visible to user space via timer_getoverrun(2) and siginfo::si_overrun, random. For example, a local user can cause a denial of service (signed integer overflow) via crafted mmap, futex, timer_create, and timer_settime system calls.
Ubuntu USN Ubuntu USN USN-3847-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3847-2 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3847-3 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-3848-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3848-2 Linux kernel (Xenial HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3849-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3849-2 Linux kernel (Trusty HWE) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T08:45:02.345Z

Reserved: 2018-06-26T00:00:00

Link: CVE-2018-12896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-02T17:29:00.660

Modified: 2024-11-21T03:46:03.597

Link: CVE-2018-12896

cve-icon Redhat

Severity :

Publid Date: 2018-06-22T00:00:00Z

Links: CVE-2018-12896 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses