Null pointer dereference in Linux kernel - CVE-2018-5333
Published: January 11, 2018 / Updated: June 17, 2021
Vulnerability identifier: #VU10001
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5333
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the rds_cmsg_atomic function due to insufficient handling of user-supplied input. A remote attacker can send a specially crafted HTTP request, trigger NULL pointer dereference and cause the system to crash.
Affected software
Linux kernel
Debian Linux
SUSE Linux
Ubuntu
Fedora
MRG Realtime
kernel
Debian Linux
SUSE Linux
Ubuntu
Fedora
MRG Realtime
kernel
How to mitigate CVE-2018-5333
Install update from vendor's website.
kernel - addressed in versions 4.14.14-200.fc26, 4.14.14-300.fc27
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Linux Kernel
- Ubuntu update for Linux kernel
- Ubuntu update for Linux kernel (Trusty HWE)
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- Debian update for linux
- Red Hat update for Red Hat Enterprise MRG Realtime 2.5
- Fedora 27 update for kernel
- Fedora 26 update for kernel