Vulnerability Description
An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | - | |
| Linux | Linux Kernel | >= 3.19, < 4.1.50 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=073c51PatchThird Party Advisory
- https://github.com/torvalds/linux/commit/073c516ff73557a8f7315066856c04b50383ac3PatchThird Party Advisory
- https://source.android.com/security/bulletin/2018-07-01Vendor Advisory
- https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=34742aaf7cb16c95Third Party Advisory
- https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-seThird Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=073c51PatchThird Party Advisory
- https://github.com/torvalds/linux/commit/073c516ff73557a8f7315066856c04b50383ac3PatchThird Party Advisory
- https://source.android.com/security/bulletin/2018-07-01Vendor Advisory
- https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=34742aaf7cb16c95Third Party Advisory
- https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-seThird Party Advisory
FAQ
What is CVE-2018-5873?
CVE-2018-5873 is a vulnerability with a CVSS score of 7.0 (HIGH). An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affect...
How severe is CVE-2018-5873?
CVE-2018-5873 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5873?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Linux Linux Kernel.