witchcraze / NVD_CHECK

1 stars 0 forks source link

CHK NVD : CVE-2018-5390 - 8d3f1652 #2705

Closed witchcraze closed 1 year ago

witchcraze commented 1 year ago

[CVE Configuration Update Request] Update Suggestion - CVE-2018-5390 - Cvss2 : 7.8 [CVE Configuration Update Request] Update Suggestion - CVE-2018-5390 - Cvss3 : 7.5

https://www.linuxkernelcves.com/cves/CVE-2018-5390 https://gitlab.com/cip-project/cip-kernel/cip-kernel-sec/-/blob/master/issues/CVE-2018-5390.yml https://github.com/witchcraze/NVD_CHECK/blob/main/kernel/CVE-2018-5390.json

- CVE-2018-5390
- Suggested Configuration
  - OR
     *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 3.18.0 up to (excluding) 3.18.117
     *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 4.14.0 up to (excluding) 4.14.59
     *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 4.17.0 up to (excluding) 4.17.11
     *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 4.4.0 up to (excluding) 4.4.145
     *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 4.4.0 up to (excluding) 4.4.161
     *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 4.9.0 up to (excluding) 4.9.116
     *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 4.9.0 up to (excluding) 4.9.119
- Reference
  - https://bugzilla.redhat.com/show_bug.cgi?id=1601704
  - https://github.com/torvalds/linux/commit/3d4bf93ac12003f9b8e1e2de37fe27983deebdcf
  - https://github.com/torvalds/linux/commit/58152ecbbcc6a0ce7fddd5bf5f6ee535834ece0c
  - https://github.com/torvalds/linux/commit/72cd43ba64fc172a443410ce01645895850844c8
  - https://github.com/torvalds/linux/commit/8541b21e781a22dce52a74fef0b9bed00404a1cd
  - https://github.com/torvalds/linux/commit/f4a3313d8e2ca9fd8d8f45e40a2903ba782607e7
  - https://www.kernel.org/pub//linux/kernel/v3.x/ChangeLog-3.18.117
  - https://www.kernel.org/pub//linux/kernel/v4.x/ChangeLog-4.14.59
  - https://www.kernel.org/pub//linux/kernel/v4.x/ChangeLog-4.17.11
  - https://www.kernel.org/pub//linux/kernel/v4.x/ChangeLog-4.4.145
  - https://www.kernel.org/pub//linux/kernel/v4.x/ChangeLog-4.4.161
  - https://www.kernel.org/pub//linux/kernel/v4.x/ChangeLog-4.9.116
  - https://www.kernel.org/pub//linux/kernel/v4.x/ChangeLog-4.9.119
- Reference (Commit)
  - tcp: detect malicious patterns in tcp_collapse_ofo_queue()
    - Fixed by
      - - (3d4bf93ac12003f9b8e1e2de37fe27983deebdcf) (upstream)
      - 3.18.117 (d932145a840ebc81e7a029a0531cad8f7a1f0932)
      - 4.14.59 (6285a74a536f1ee807488436547cc17cda3306d8)
      - 4.17.11 (81a4582f7dc8c3fbf06b2cb6c0bc13d8f372c637)
      - 4.4.145 (dc6ae4dffd656811dee7151b19545e4cd839d378)
      - 4.9.116 (a878681484a0992ee3dfbd7826439951f9f82a69)
    - Will be introduced by
      - 2.6.12 (1da177e4c3f4)
  - tcp: avoid collapses in tcp_prune_queue() if possible
    - Fixed by
      - - (f4a3313d8e2ca9fd8d8f45e40a2903ba782607e7) (upstream)
      - 3.18.117 (25c28af9ee6a9cfeeb9245e174b3b65d70e614b2)
      - 4.14.59 (81e6b01d1c10015811f52bf04ec125bdb291b4b5)
      - 4.17.11 (4971f342bd35500fa71d1cbbcc610524ef0a7531)
      - 4.4.145 (5fbec4801264cb3279ef6ac9c70bcbe2aaef89d5)
      - 4.9.116 (fdf258ed5dd85b57cf0e0e66500be98d38d42d02)
    - Will be introduced by
      - 2.6.12 (1da177e4c3f4)
  - tcp: add tcp_ooo_try_coalesce() helper
    - Fixed by
      - - (58152ecbbcc6a0ce7fddd5bf5f6ee535834ece0c) (upstream)
      - 4.14.59 (22e3d3178b18115ba60cae7c968a67718f070da0)
      - 4.17.11 (840e03915bcd08a103beed7c4ee3b78989570aed)
      - 4.4.161 (eee1af4e268e10fecb76bce42a8d7343aeb2a5e6)
      - 4.9.119 (36ee106e844187e3fc612c9b87f12e5e23e9d8a5)
    - Will be introduced by
  - tcp: call tcp_drop() from tcp_data_queue_ofo()
    - Fixed by
      - - (8541b21e781a22dce52a74fef0b9bed00404a1cd) (upstream)
      - 4.14.59 (ec645ae62309a85522c2bc8f700afc6e152e62b9)
      - 4.17.11 (9ad090e6d0eecdc7978de4f952ff93676b2fcd03)
      - 4.4.161 (be288481479ca8c1beba02a7e779ffeaa11f1597)
      - 4.9.116 (94623c7463f3424776408df2733012c42b52395a)
    - Will be introduced by
      - 4.4.161 (4666b6e2b27d)
      - https://github.com/torvalds/linux/commit/9f5afeae5152
  - tcp: free batches of packets in tcp_prune_ofo_queue()
    - Fixed by
      - - (72cd43ba64fc172a443410ce01645895850844c8) (upstream)
      - 4.14.59 (f3a5ba6310e11df370f6888ed716d1486896d983)
      - 4.17.11 (db11182a1e38e7149804962111622b15bd9aeff2)
      - 4.4.161 (352b66932a23fb11f0a7c316361220648bca3c79)
      - 4.9.116 (2d08921c8da26bdce3d8848ef6f32068f594d7d4)
    - Will be introduced by
      - https://github.com/torvalds/linux/commit/36a6503fedda
- I Checked
  - XXXXXXXXXXXXXXXXXXXXXXXXXXXX is written as upstream commit in each ChangeLog
  - From XXXXXXXX commit page, XXXXXXXXXXX is the most oldest in commit-branches area
  - For 3.16.35, there is related post at lkml
  - For 3.16 series, 3.16.35 is the next release from 3.16.7 which was released at 2014
  - https://mirrors.edge.kernel.org/pub/linux/kernel/v3.x/
  - XXXX
https://nvd.nist.gov/vuln/detail/CVE-2018-5390 URI Start(Ex) Start(Inc) End(Ex) End(Inc)
cpe:/o:redhat:enterprise_linux_workstation:7.0
cpe:/o:redhat:enterprise_linux_server_tus:7.4
cpe:/o:redhat:enterprise_linux_server_tus:7.3
cpe:/o:redhat:enterprise_linux_server_tus:7.2
cpe:/o:redhat:enterprise_linux_server_tus:6.6
cpe:/o:redhat:enterprise_linux_server_eus:7.5
cpe:/o:redhat:enterprise_linux_server_eus:7.4
cpe:/o:redhat:enterprise_linux_server_eus:7.3
cpe:/o:redhat:enterprise_linux_server_eus:7.2
cpe:/o:redhat:enterprise_linux_server_eus:6.7
cpe:/o:redhat:enterprise_linux_server_eus:6.4
cpe:/o:redhat:enterprise_linux_server_aus:7.4
cpe:/o:redhat:enterprise_linux_server_aus:7.3
cpe:/o:redhat:enterprise_linux_server_aus:7.2
cpe:/o:redhat:enterprise_linux_server_aus:6.6
cpe:/o:redhat:enterprise_linux_server_aus:6.5
cpe:/o:redhat:enterprise_linux_server_aus:6.4
cpe:/o:redhat:enterprise_linux_server:7.0
cpe:/o:redhat:enterprise_linux_desktop:7.0
cpe:/o:linux:linux_kernel:4.18:rc6
cpe:/o:linux:linux_kernel:4.18:rc5
cpe:/o:linux:linux_kernel:4.18:rc4
cpe:/o:linux:linux_kernel:4.18:rc3
cpe:/o:linux:linux_kernel:4.18:rc2
cpe:/o:linux:linux_kernel:4.18:rc1
cpe:/o:linux:linux_kernel 4.9 4.18
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:8.0
cpe:/o:cisco:telepresence_video_communication_server_firmware:x8.11
cpe:/o:cisco:telepresence_video_communication_server_firmware:x8.10.4
cpe:/o:cisco:telepresence_video_communication_server_firmware:x8.10.3
cpe:/o:cisco:telepresence_video_communication_server_firmware:x8.10.2
cpe:/o:cisco:telepresence_video_communication_server_firmware:x8.10.1
cpe:/o:cisco:telepresence_video_communication_server_firmware:x8.10
cpe:/o:cisco:telepresence_conductor_firmware:xc4.3.4
cpe:/o:cisco:telepresence_conductor_firmware:xc4.3.3
cpe:/o:cisco:telepresence_conductor_firmware:xc4.3.2
cpe:/o:cisco:telepresence_conductor_firmware:xc4.3.1
cpe:/o:cisco:telepresence_conductor_firmware:xc4.3
cpe:/o:canonical:ubuntu_linux:18.04::lts~
cpe:/o:canonical:ubuntu_linux:16.04::lts~
cpe:/o:canonical:ubuntu_linux:14.04::lts~
cpe:/o:canonical:ubuntu_linux:12.04::esm~
cpe:/o:a10networks:advanced_core_operating_system:4.1.4:p1
cpe:/o:a10networks:advanced_core_operating_system:4.1.4
cpe:/o:a10networks:advanced_core_operating_system:4.1.2:p4
cpe:/o:a10networks:advanced_core_operating_system:4.1.2
cpe:/o:a10networks:advanced_core_operating_system:4.1.1:p8
cpe:/o:a10networks:advanced_core_operating_system:4.1.0:p11
cpe:/o:a10networks:advanced_core_operating_system:4.1.0
cpe:/o:a10networks:advanced_core_operating_system:3.2.2:p5
cpe:/o:a10networks:advanced_core_operating_system:3.2.2
cpe:/a:redhat:virtualization:4.0
cpe:/a:hp:aruba_clearpass_policy_manager 6.6.0 6.6.9
cpe:/a:hp:aruba_clearpass_policy_manager 6.7.0 6.7.5
cpe:/a:hp:aruba_airwave_amp 8.2.7.1
cpe:/a:f5:traffix_systems_signaling_delivery_controller:4.4.0
cpe:/a:f5:traffix_systems_signaling_delivery_controller 5.0.0 5.1.0
cpe:/a:f5:big-ip_webaccelerator:14.0.0
cpe:/a:f5:big-ip_webaccelerator 11.5.1 11.6.3
cpe:/a:f5:big-ip_webaccelerator 12.1.0 12.1.3
cpe:/a:f5:big-ip_webaccelerator 13.0.0 13.1.1
cpe:/a:f5:big-ip_policy_enforcement_manager:14.0.0
cpe:/a:f5:big-ip_policy_enforcement_manager 11.5.1 11.6.3
cpe:/a:f5:big-ip_policy_enforcement_manager 12.1.0 12.1.3
cpe:/a:f5:big-ip_policy_enforcement_manager 13.0.0 13.1.1
cpe:/a:f5:big-ip_local_traffic_manager:14.0.0
cpe:/a:f5:big-ip_local_traffic_manager 11.5.1 11.6.3
cpe:/a:f5:big-ip_local_traffic_manager 12.0.0 12.1.3
cpe:/a:f5:big-ip_local_traffic_manager 13.0.0 13.1.1
cpe:/a:f5:big-ip_link_controller:14.0.0
cpe:/a:f5:big-ip_link_controller 11.5.1 11.6.3
cpe:/a:f5:big-ip_link_controller 12.1.0 12.1.3
cpe:/a:f5:big-ip_link_controller 13.0.0 13.1.1
cpe:/a:f5:big-ip_global_traffic_manager:14.0.0
cpe:/a:f5:big-ip_global_traffic_manager 11.5.1 11.6.3
cpe:/a:f5:big-ip_global_traffic_manager 12.1.0 12.1.3
cpe:/a:f5:big-ip_global_traffic_manager 13.0.0 13.1.1
cpe:/a:f5:big-ip_fraud_protection_service:14.0.0
cpe:/a:f5:big-ip_fraud_protection_service 11.5.1 11.6.3
cpe:/a:f5:big-ip_fraud_protection_service 12.1.0 12.1.3
cpe:/a:f5:big-ip_fraud_protection_service 13.0.0 13.1.1
cpe:/a:f5:big-ip_edge_gateway:14.0.0
cpe:/a:f5:big-ip_edge_gateway 11.5.1. 11.6.3
cpe:/a:f5:big-ip_edge_gateway 12.1.0 12.1.3
cpe:/a:f5:big-ip_edge_gateway 13.0.0 13.1.1
cpe:/a:f5:big-ip_domain_name_system:14.0.0
cpe:/a:f5:big-ip_domain_name_system 11.5.1 11.6.3
cpe:/a:f5:big-ip_domain_name_system 12.1.0 12.1.3
cpe:/a:f5:big-ip_domain_name_system 13.0.0 13.1.1
cpe:/a:f5:big-ip_application_security_manager:14.0.0
cpe:/a:f5:big-ip_application_security_manager 11.5.1 11.6.3
cpe:/a:f5:big-ip_application_security_manager 12.1.0 12.1.3
cpe:/a:f5:big-ip_application_security_manager 13.0.0 13.1.1
cpe:/a:f5:big-ip_application_acceleration_manager:14.0.0
cpe:/a:f5:big-ip_application_acceleration_manager 11.5.1 11.6.3
cpe:/a:f5:big-ip_application_acceleration_manager 12.1.0 12.1.3
cpe:/a:f5:big-ip_application_acceleration_manager 13.0.0 13.1.1
cpe:/a:f5:big-ip_analytics:14.0.0
cpe:/a:f5:big-ip_analytics 11.5.1 11.6.3
cpe:/a:f5:big-ip_analytics 12.1.0 12.1.3
cpe:/a:f5:big-ip_analytics 13.0.0 13.1.1
cpe:/a:f5:big-ip_advanced_firewall_manager:14.0.0
cpe:/a:f5:big-ip_advanced_firewall_manager 11.5.1 11.6.3
cpe:/a:f5:big-ip_advanced_firewall_manager 12.1.0 12.1.3
cpe:/a:f5:big-ip_advanced_firewall_manager 13.0.0 13.1.1
cpe:/a:f5:big-ip_access_policy_manager:14.0.0
cpe:/a:f5:big-ip_access_policy_manager 11.5.1 11.6.3
cpe:/a:f5:big-ip_access_policy_manager 12.1.0 12.1.3
cpe:/a:f5:big-ip_access_policy_manager 13.0.0 13.1.1
cpe:/a:cisco:webex_video_mesh:-
cpe:/a:cisco:webex_hybrid_data_security:-
cpe:/a:cisco:threat_grid-cloud:-
cpe:/a:cisco:network_assurance_engine:2.1%281a%29
cpe:/a:cisco:meeting_management:1.0.1
cpe:/a:cisco:meeting_management:1.0
cpe:/a:cisco:expressway_series:-
cpe:/a:cisco:expressway:x8.11
cpe:/a:cisco:expressway:x8.10.4
cpe:/a:cisco:expressway:x8.10.3
cpe:/a:cisco:expressway:x8.10.2
cpe:/a:cisco:expressway:x8.10.1
cpe:/a:cisco:expressway:x8.10
cpe:/a:cisco:digital_network_architecture_center:1.2
cpe:/a:cisco:collaboration_meeting_rooms:1.0
witchcraze commented 1 year ago

introduceが取れていない