CVE-2018-10689
Summary
| CVE | CVE-2018-10689 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-03 07:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| kernel/git/axboe/blktrace.git - blktrace/parse repo |
MISC |
git.kernel.org |
Patch |
| blktrace: Buffer overflow (GLSA 202107-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| A heap overflow in blktrace — Linux Btrace |
MISC |
www.spinics.net |
Mailing List, Third Party Advisory |
| git.kernel.dk Git - blktrace.git/log |
|
git.kernel.dk |
|
| Blktrace 'btt/devmap.c' Local Buffer Overflow Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| git.kernel.dk Git - blktrace.git/log |
MISC |
git.kernel.dk |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377522 Alibaba Cloud Linux Security Update for blktrace (ALINUX2-SA-2019:0056)
- 670362 EulerOS Security Update for blktrace (EulerOS-SA-2021-1768)
- 670598 EulerOS Security Update for blktrace (EulerOS-SA-2021-2356)
- 710061 Gentoo Linux blktrace Buffer overflow (GLSA 202107-15)
- 900247 CBL-Mariner Linux Security Update for blktrace 1.2.0
- 901573 Common Base Linux Mariner (CBL-Mariner) Security Update for blktrace (6328-1)
- 903341 Common Base Linux Mariner (CBL-Mariner) Security Update for blktrace (1802)