Skip to content

[SECURITY] cdrom: fix improper type cast causing info leak (CVE-2018-18710)#127

Open
Mifacopy wants to merge 1 commit intofacebookincubator:oculus-go-kernel-masterfrom
Mifacopy:patch-24
Open

[SECURITY] cdrom: fix improper type cast causing info leak (CVE-2018-18710)#127
Mifacopy wants to merge 1 commit intofacebookincubator:oculus-go-kernel-masterfrom
Mifacopy:patch-24

Conversation

@Mifacopy
Copy link

Fix CVE-2018-18710.

Upstream commit: e4f3aa2e1e67bb48dfbaaf1cad59013d5a5bc276

cdrom_ioctl_select_disc() performed a bounds check after casting the user-
controlled argument from unsigned long to int. The cast could invalidate the
check, allowing an out-of-range value to be used later and potentially leak
kernel memory (information disclosure). This issue is similar to
CVE-2018-16658 and CVE-2018-10940.

Reference: CVE-2018-18710

@meta-cla meta-cla bot added the CLA Signed Do not delete this pull request or issue due to inactivity. label Feb 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed Do not delete this pull request or issue due to inactivity.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant