CVE-2018-10883

Source
https://cve.org/CVERecord?id=CVE-2018-10883
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-10883.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-10883
Downstream
Related
Published
2018-07-30T16:29:00.220Z
Modified
2026-02-11T08:19:04.603070Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2journaldirty_metadata(), a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
8bc1379b82b8e809eef77a9fedbb75c6c297be19
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
e09463f220ca9a1a1ecfda84fcda658f99a1f12a

Affected versions

v2.*
v2.6.12
v2.6.12-rc2
v2.6.12-rc3
v2.6.12-rc4
v2.6.12-rc5
v2.6.12-rc6
v2.6.13
v2.6.13-rc1
v2.6.13-rc2
v2.6.13-rc3
v2.6.13-rc4
v2.6.13-rc5
v2.6.13-rc6
v2.6.13-rc7
v2.6.14
v2.6.14-rc1
v2.6.14-rc2
v2.6.14-rc3
v2.6.14-rc4
v2.6.14-rc5
v2.6.15
v2.6.15-rc1
v2.6.15-rc2
v2.6.15-rc3
v2.6.15-rc4
v2.6.15-rc5
v2.6.15-rc6
v2.6.15-rc7
v2.6.16
v2.6.16-rc1
v2.6.16-rc2
v2.6.16-rc3
v2.6.16-rc4
v2.6.16-rc5
v2.6.16-rc6
v2.6.17
v2.6.17-rc1
v2.6.17-rc2
v2.6.17-rc3
v2.6.17-rc4
v2.6.17-rc5
v2.6.17-rc6
v2.6.18
v2.6.18-rc1
v2.6.18-rc2
v2.6.18-rc3
v2.6.18-rc4
v2.6.18-rc5
v2.6.18-rc6
v2.6.18-rc7
v2.6.19
v2.6.19-rc1
v2.6.19-rc2
v2.6.19-rc3
v2.6.19-rc4
v2.6.19-rc5
v2.6.19-rc6
v2.6.20
v2.6.20-rc1
v2.6.20-rc2
v2.6.20-rc3
v2.6.20-rc4
v2.6.20-rc5
v2.6.20-rc6
v2.6.20-rc7
v2.6.21
v2.6.21-rc1
v2.6.21-rc2
v2.6.21-rc3
v2.6.21-rc4
v2.6.21-rc5
v2.6.21-rc6
v2.6.21-rc7
v2.6.22
v2.6.22-rc1
v2.6.22-rc2
v2.6.22-rc3
v2.6.22-rc4
v2.6.22-rc5
v2.6.22-rc6
v2.6.22-rc7
v2.6.23
v2.6.23-rc1
v2.6.23-rc2
v2.6.23-rc3
v2.6.23-rc4
v2.6.23-rc5
v2.6.23-rc6
v2.6.23-rc7
v2.6.23-rc8
v2.6.23-rc9
v2.6.24
v2.6.24-rc1
v2.6.24-rc2
v2.6.24-rc3
v2.6.24-rc4
v2.6.24-rc5
v2.6.24-rc6
v2.6.24-rc7
v2.6.24-rc8
v2.6.25
v2.6.25-rc1
v2.6.25-rc2
v2.6.25-rc3
v2.6.25-rc4
v2.6.25-rc5
v2.6.25-rc6
v2.6.25-rc7
v2.6.25-rc8
v2.6.25-rc9
v2.6.26
v2.6.26-rc1
v2.6.26-rc2
v2.6.26-rc3
v2.6.26-rc4
v2.6.26-rc5
v2.6.26-rc6
v2.6.26-rc7
v2.6.26-rc8
v2.6.26-rc9
v2.6.27
v2.6.27-rc1
v2.6.27-rc2
v2.6.27-rc3
v2.6.27-rc4
v2.6.27-rc5
v2.6.27-rc6
v2.6.27-rc7
v2.6.27-rc8
v2.6.27-rc9
v2.6.28
v2.6.28-rc1
v2.6.28-rc2
v2.6.28-rc3
v2.6.28-rc4
v2.6.28-rc5
v2.6.28-rc6
v2.6.28-rc7
v2.6.28-rc8
v2.6.28-rc9
v2.6.29
v2.6.29-rc1
v2.6.29-rc2
v2.6.29-rc3
v2.6.29-rc4
v2.6.29-rc5
v2.6.29-rc6
v2.6.29-rc7
v2.6.29-rc8
v2.6.30
v2.6.30-rc1
v2.6.30-rc2
v2.6.30-rc3
v2.6.30-rc4
v2.6.30-rc5
v2.6.30-rc6
v2.6.30-rc7
v2.6.30-rc8
v2.6.31
v2.6.31-rc1
v2.6.31-rc2
v2.6.31-rc3
v2.6.31-rc4
v2.6.31-rc5
v2.6.31-rc6
v2.6.31-rc7
v2.6.31-rc8
v2.6.31-rc9
v2.6.32
v2.6.32-rc1
v2.6.32-rc2
v2.6.32-rc3
v2.6.32-rc4
v2.6.32-rc5
v2.6.32-rc6
v2.6.32-rc7
v2.6.32-rc8
v2.6.33
v2.6.33-rc1
v2.6.33-rc2
v2.6.33-rc3
v2.6.33-rc4
v2.6.33-rc5
v2.6.33-rc6
v2.6.33-rc7
v2.6.33-rc8
v2.6.34
v2.6.34-rc1
v2.6.34-rc2
v2.6.34-rc3
v2.6.34-rc4
v2.6.34-rc5
v2.6.34-rc6
v2.6.34-rc7
v2.6.35
v2.6.35-rc1
v2.6.35-rc2
v2.6.35-rc3
v2.6.35-rc4
v2.6.35-rc5
v2.6.35-rc6
v2.6.36
v2.6.36-rc1
v2.6.36-rc2
v2.6.36-rc3
v2.6.36-rc4
v2.6.36-rc5
v2.6.36-rc6
v2.6.36-rc7
v2.6.36-rc8
v2.6.37
v2.6.37-rc1
v2.6.37-rc2
v2.6.37-rc3
v2.6.37-rc4
v2.6.37-rc5
v2.6.37-rc6
v2.6.37-rc7
v2.6.37-rc8
v2.6.38
v2.6.38-rc1
v2.6.38-rc2
v2.6.38-rc3
v2.6.38-rc4
v2.6.38-rc5
v2.6.38-rc6
v2.6.38-rc7
v2.6.38-rc8
v2.6.39
v2.6.39-rc1
v2.6.39-rc2
v2.6.39-rc3
v2.6.39-rc4
v2.6.39-rc5
v2.6.39-rc6
v2.6.39-rc7
v3.*
v3.0
v3.0-rc1
v3.0-rc2
v3.0-rc3
v3.0-rc4
v3.0-rc5
v3.0-rc6
v3.0-rc7
v3.1
v3.1-rc1
v3.1-rc10
v3.1-rc2
v3.1-rc3
v3.1-rc4
v3.1-rc5
v3.1-rc6
v3.1-rc7
v3.1-rc8
v3.1-rc9
v3.10
v3.10-rc1
v3.10-rc2
v3.10-rc3
v3.10-rc4
v3.10-rc5
v3.10-rc6
v3.10-rc7
v3.11
v3.11-rc1
v3.11-rc2
v3.11-rc3
v3.11-rc4
v3.11-rc5
v3.11-rc6
v3.11-rc7
v3.12
v3.12-rc1
v3.12-rc2
v3.12-rc3
v3.12-rc4
v3.12-rc5
v3.12-rc6
v3.12-rc7
v3.13
v3.13-rc1
v3.13-rc2
v3.13-rc3
v3.13-rc4
v3.13-rc5
v3.13-rc6
v3.13-rc7
v3.13-rc8
v3.14
v3.14-rc1
v3.14-rc2
v3.14-rc3
v3.14-rc4
v3.14-rc5
v3.14-rc6
v3.14-rc7
v3.14-rc8
v3.15
v3.15-rc1
v3.15-rc2
v3.15-rc3
v3.15-rc4
v3.15-rc5
v3.15-rc6
v3.15-rc7
v3.15-rc8
v3.16
v3.16-rc1
v3.16-rc2
v3.16-rc3
v3.16-rc4
v3.16-rc5
v3.16-rc6
v3.16-rc7
v3.17
v3.17-rc1
v3.17-rc2
v3.17-rc3
v3.17-rc4
v3.17-rc5
v3.17-rc6
v3.17-rc7
v3.18
v3.18-rc1
v3.18-rc2
v3.18-rc3
v3.18-rc4
v3.18-rc5
v3.18-rc6
v3.18-rc7
v3.19
v3.19-rc1
v3.19-rc2
v3.19-rc3
v3.19-rc4
v3.19-rc5
v3.19-rc6
v3.19-rc7
v3.2
v3.2-rc1
v3.2-rc2
v3.2-rc3
v3.2-rc4
v3.2-rc5
v3.2-rc6
v3.2-rc7
v3.3
v3.3-rc1
v3.3-rc2
v3.3-rc3
v3.3-rc4
v3.3-rc5
v3.3-rc6
v3.3-rc7
v3.4
v3.4-rc1
v3.4-rc2
v3.4-rc3
v3.4-rc4
v3.4-rc5
v3.4-rc6
v3.4-rc7
v3.5
v3.5-rc1
v3.5-rc2
v3.5-rc3
v3.5-rc4
v3.5-rc5
v3.5-rc6
v3.5-rc7
v3.6
v3.6-rc1
v3.6-rc2
v3.6-rc3
v3.6-rc4
v3.6-rc5
v3.6-rc6
v3.6-rc7
v3.7
v3.7-rc1
v3.7-rc2
v3.7-rc3
v3.7-rc4
v3.7-rc5
v3.7-rc6
v3.7-rc7
v3.7-rc8
v3.8
v3.8-rc1
v3.8-rc2
v3.8-rc3
v3.8-rc4
v3.8-rc5
v3.8-rc6
v3.8-rc7
v3.9
v3.9-rc1
v3.9-rc2
v3.9-rc3
v3.9-rc4
v3.9-rc5
v3.9-rc6
v3.9-rc7
v3.9-rc8
v4.*
v4.0
v4.0-rc1
v4.0-rc2
v4.0-rc3
v4.0-rc4
v4.0-rc5
v4.0-rc6
v4.0-rc7
v4.1
v4.1-rc1
v4.1-rc2
v4.1-rc3
v4.1-rc4
v4.1-rc5
v4.1-rc6
v4.1-rc7
v4.1-rc8
v4.10
v4.10-rc1
v4.10-rc2
v4.10-rc3
v4.10-rc4
v4.10-rc5
v4.10-rc6
v4.10-rc7
v4.10-rc8
v4.11
v4.11-rc1
v4.11-rc2
v4.11-rc3
v4.11-rc4
v4.11-rc5
v4.11-rc6
v4.11-rc7
v4.11-rc8
v4.12
v4.12-rc1
v4.12-rc2
v4.12-rc3
v4.12-rc4
v4.12-rc5
v4.12-rc6
v4.12-rc7
v4.13
v4.13-rc1
v4.13-rc2
v4.13-rc3
v4.13-rc4
v4.13-rc5
v4.13-rc6
v4.13-rc7
v4.14
v4.14-rc1
v4.14-rc2
v4.14-rc3
v4.14-rc4
v4.14-rc5
v4.14-rc6
v4.14-rc7
v4.14-rc8
v4.15
v4.15-rc1
v4.15-rc2
v4.15-rc3
v4.15-rc4
v4.15-rc5
v4.15-rc6
v4.15-rc7
v4.15-rc8
v4.15-rc9
v4.16
v4.16-rc1
v4.16-rc2
v4.16-rc3
v4.16-rc4
v4.16-rc5
v4.16-rc6
v4.16-rc7
v4.17-rc1
v4.17-rc2
v4.17-rc3
v4.17-rc4
v4.2
v4.2-rc1
v4.2-rc2
v4.2-rc3
v4.2-rc4
v4.2-rc5
v4.2-rc6
v4.2-rc7
v4.2-rc8
v4.3
v4.3-rc1
v4.3-rc2
v4.3-rc3
v4.3-rc4
v4.3-rc5
v4.3-rc6
v4.3-rc7
v4.4
v4.4-rc1
v4.4-rc2
v4.4-rc3
v4.4-rc4
v4.4-rc5
v4.4-rc6
v4.4-rc7
v4.4-rc8
v4.5
v4.5-rc1
v4.5-rc2
v4.5-rc3
v4.5-rc4
v4.5-rc5
v4.5-rc6
v4.5-rc7
v4.6
v4.6-rc1
v4.6-rc2
v4.6-rc3
v4.6-rc4
v4.6-rc5
v4.6-rc6
v4.6-rc7
v4.7
v4.7-rc1
v4.7-rc2
v4.7-rc3
v4.7-rc4
v4.7-rc5
v4.7-rc6
v4.7-rc7
v4.8
v4.8-rc1
v4.8-rc2
v4.8-rc3
v4.8-rc4
v4.8-rc5
v4.8-rc6
v4.8-rc7
v4.8-rc8
v4.9
v4.9-rc1
v4.9-rc2
v4.9-rc3
v4.9-rc4
v4.9-rc5
v4.9-rc6
v4.9-rc7
v4.9-rc8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-10883.json"
vanir_signatures
[
    {
        "target": {
            "file": "fs/ext4/ext4.h"
        },
        "digest": {
            "line_hashes": [
                "233085780273812737718107874144801903017",
                "187078644615943984562828088934017676170",
                "324957208477898816983488729543413229742",
                "320055824807714710030453052483311950141",
                "13880585924166837488152185439201543710",
                "30385317121471278946074722202098197747"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "id": "CVE-2018-10883-21975c93",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@8bc1379b82b8e809eef77a9fedbb75c6c297be19",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "target": {
            "file": "fs/ext4/inline.c"
        },
        "digest": {
            "line_hashes": [
                "13793893303274874404186523655264847719",
                "163841345070282288138140860922295376727",
                "68302215105809065861689536006754290904",
                "302738163183306791072712481284030671876",
                "300754818274104696496217100648285783663",
                "2553424655721862809078088512723651083",
                "197525883078775835224356454723140213460",
                "154349553750416272296086562575027067610",
                "145664673674066924911453930330355901413",
                "70836968979291670965321459240589083967",
                "150789893979504237138889426467549034052",
                "330493446494439317513349252404128347270",
                "93044119187154653227045592263967867905",
                "110748094791911114859272415208184245006",
                "624749358110798394361616054424325547",
                "16465270641858440594211974997806096984",
                "247629963672729417741299221166898786996",
                "152536487844037155915278776354144237241",
                "207178349110495355199780937030181517293",
                "336429856375769676617030544366697818226",
                "128591540987782557622689517343728744608",
                "311369002813699814107988221268579990079",
                "301690729491479828997262719953601607342",
                "240024096526761051259352375521209254615",
                "311612015724040725986096166052806618384",
                "72238614288822761734528381628794427334",
                "60808820776553746377904592341021797352",
                "311709111690206774850991135766931052799",
                "313356390481514841937206248196630951383",
                "269041368106091485006916327989942059123",
                "313128834135678505408364336124120172765",
                "268847027717103580994541856889302450418",
                "84394351737831327706137815641665541748",
                "259197591672411050401831699192803820634",
                "157898943701272340300770437460490864421",
                "269214579928503244948469963729074449950"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "id": "CVE-2018-10883-41b4dcc7",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@8bc1379b82b8e809eef77a9fedbb75c6c297be19",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "target": {
            "file": "fs/ext4/xattr.c",
            "function": "ext4_xattr_ibody_inline_set"
        },
        "digest": {
            "length": 891.0,
            "function_hash": "175976546872251417913444657634961502518"
        },
        "signature_type": "Function",
        "id": "CVE-2018-10883-7336bf86",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@8bc1379b82b8e809eef77a9fedbb75c6c297be19",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "target": {
            "file": "fs/ext4/inline.c",
            "function": "ext4_da_write_inline_data_begin"
        },
        "digest": {
            "length": 1384.0,
            "function_hash": "293794837482046420697231874777572132428"
        },
        "signature_type": "Function",
        "id": "CVE-2018-10883-8621064a",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@8bc1379b82b8e809eef77a9fedbb75c6c297be19",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "target": {
            "file": "fs/ext4/inline.c",
            "function": "ext4_try_to_evict_inline_data"
        },
        "digest": {
            "length": 493.0,
            "function_hash": "301305360827463244514272327124350024020"
        },
        "signature_type": "Function",
        "id": "CVE-2018-10883-9a18cffb",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@8bc1379b82b8e809eef77a9fedbb75c6c297be19",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "target": {
            "file": "fs/jbd2/transaction.c",
            "function": "jbd2_journal_dirty_metadata"
        },
        "digest": {
            "length": 2695.0,
            "function_hash": "272429099031414448037239403748223925028"
        },
        "signature_type": "Function",
        "id": "CVE-2018-10883-c31f61a2",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@e09463f220ca9a1a1ecfda84fcda658f99a1f12a",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "target": {
            "file": "fs/ext4/xattr.c"
        },
        "digest": {
            "line_hashes": [
                "20167569701269110198679413784380622052",
                "185987473919149189916497316094433496900",
                "19449044704018144262478044734079276735",
                "91502599425582228998970399209869881123",
                "307362065818964216317081283198868551108",
                "247830973363813568520705998125364738670",
                "284587928340878127929936210252894971442",
                "89617643806854152018852347647339408283",
                "132559211588898863607352845925589912413",
                "256321183518428493103970940038873052464",
                "159530583954515619725370341396087968557",
                "105506256532816798725597532156476935441",
                "310176209826636425170910584891871689666",
                "89703325029247827723945210130855945423",
                "239490179093844120316924862388215239674",
                "300394734543566261771441247488054473042",
                "117411397033308978074643833343762036968",
                "14113538881332881556509852003662805271",
                "86012737292886068508236449494282820109",
                "188023801999886744687966115532392881730"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "id": "CVE-2018-10883-e2cd3b37",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@8bc1379b82b8e809eef77a9fedbb75c6c297be19",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "target": {
            "file": "fs/jbd2/transaction.c"
        },
        "digest": {
            "line_hashes": [
                "74761795778547930566917813860130109074",
                "60322540319384413523315366012959833647",
                "284438372858346332744679272024932677869",
                "246750953741505428356985565567225903287",
                "151890875588582939850705559843013677058",
                "262047433257021078340568059659197149574",
                "42898357787268084840079713550290525530",
                "230540739907467543937059734000108173200",
                "242664345323255969161274287155748916105",
                "321892893195742831055592522312799921079",
                "282309306785468122206594129849293472113",
                "193487741691375018257096549618151484713"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "id": "CVE-2018-10883-fae7a9fd",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@e09463f220ca9a1a1ecfda84fcda658f99a1f12a",
        "deprecated": false,
        "signature_version": "v1"
    }
]