CVE-2018-16862
Summary
| CVE | CVE-2018-16862 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-26 19:29:00 UTC |
| Updated | 2019-04-01 21:29:00 UTC |
| Description | A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of the new one. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3879-2: Linux kernel (Xenial HWE) vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| mm: cleancache: fix corruption on missed inode invalidation - Patchwork |
CONFIRM |
lore.kernel.org |
Issue Tracking, Patch, Vendor Advisory |
| USN-3879-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Linux Kernel CVE-2018-16862 Local Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 1715-1] linux-4.9 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1731-2] linux regression update |
MLIST |
lists.debian.org |
|
| USN-4118-1: Linux kernel (AWS) vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] [DLA 1731-1] linux security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| USN-4094-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| 1649017 – (CVE-2018-16862) CVE-2018-16862 kernel: cleancache: Infoleak of deleted files after reuse of old inodes |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| oss-sec: CVE-2018-16862: Linux kernel: cleancache: deleted files infoleak |
MLIST |
seclists.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 610324 Google Android March 2021 Security Patch Missing for Huawei EMUI