IBM Support

Security Bulletin: Vulnerability in kernel affects Power Hardware Management Console (CVE-2018-14633)

Security Bulletin


Summary

Power Hardware Management Console is affected by security vulnerabilities in the Linux Kernel. Power Hardware Management Console has addressed the applicable CVE.

Vulnerability Details

CVEID:  CVE-2018-14633
DESCRIPTION: A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depending on how the target's code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead to a system crash and thus to a denial-of-service or possibly to a non-authorized access to data exported by an iSCSI target. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is highly unlikely. Kernel versions 4.18.x, 4.14.x and 3.10.x are believed to be vulnerable.
CVSS Base Score: 7
CVSS Environmental Score*: Undefined
CVSS Vector: ( CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H )

Affected Products and Versions

Power HMC V8.7.0.0
Power HMC V9.1.930.0

Remediation/Fixes

Remediation/Fixes

  The following fixes are available on IBM Fix Central at: http://www-933.ibm.com/support/fixcentral/

Product
VRMF
APAR
Remediation/Fix
Power HMC
V8.8.7.1 SP3 ppc
MB04210
Power HMC
V8.8.7.1 SP3 x86
MB04209
Power HMC
V9.1.930.1  SP1 ppc
MB04213
Power HMC
V9.1.930.0  SP1 x86
MB04212

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

Initial Version: 19 June 2019

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SGGSNP","label":"Hardware Management Console V9"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
22 September 2021

UID

ibm10956425