Vulnerability Description
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 4.16 |
| Canonical | Ubuntu Linux | 16.04 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/104055Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1108Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3718-1/Third Party Advisory
- https://usn.ubuntu.com/3718-2/Third Party Advisory
- https://usn.ubuntu.com/3752-1/Third Party Advisory
- https://usn.ubuntu.com/3752-2/Third Party Advisory
- https://usn.ubuntu.com/3752-3/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4188Third Party Advisory
- http://www.securityfocus.com/bid/104055Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1108Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3718-1/Third Party Advisory
- https://usn.ubuntu.com/3718-2/Third Party Advisory
- https://usn.ubuntu.com/3752-1/Third Party Advisory
FAQ
What is CVE-2018-1108?
CVE-2018-1108 is a vulnerability with a CVSS score of 5.9 (MEDIUM). kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the...
How severe is CVE-2018-1108?
CVE-2018-1108 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1108?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Canonical Ubuntu Linux, Debian Debian Linux.