Use-after-free error in Linux kernel - CVE-2018-5344
Published: February 26, 2018
Vulnerability identifier: #VU10725
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5344
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause a DoS condition on the target system.
The weakness exists in the drivers/block/loop.c mishandles lo_release serialization due to use-after-free error. A local attacker can trigger memory corruption and cause the service to crash or execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the drivers/block/loop.c mishandles lo_release serialization due to use-after-free error. A local attacker can trigger memory corruption and cause the service to crash or execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Linux kernel
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Ubuntu
Fedora
kernel-alt (Red Hat package)
kernel
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Ubuntu
Fedora
kernel-alt (Red Hat package)
kernel
How to mitigate CVE-2018-5344
Install update from vendor's website.
kernel-alt (Red Hat package) - update to 4.14.0-115.el7a
kernel - addressed in versions 4.14.14-200.fc26, 4.14.14-300.fc27
kernel - addressed in versions 4.14.14-200.fc26, 4.14.14-300.fc27