Null pointer dereference in Linux kernel - CVE-2018-5333

 

Null pointer dereference in Linux kernel - CVE-2018-5333

Published: January 11, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU10001
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5333
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the rds_cmsg_atomic function due to insufficient handling of user-supplied input. A remote attacker can send a specially crafted HTTP request, trigger NULL pointer dereference and cause the system to crash.


Affected software

Linux kernel
Debian Linux
SUSE Linux
Ubuntu
Fedora
MRG Realtime
kernel

How to mitigate CVE-2018-5333

Install update from vendor's website.

kernel - addressed in versions 4.14.14-200.fc26, 4.14.14-300.fc27

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins