Memory corruption in Linux kernel - CVE-2018-5803
Published: March 2, 2018 / Updated: March 21, 2018
Vulnerability identifier: #VU10812
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5803
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists in the _sctp_make_chunk() function due to boundary error. A local attacker can submit a crafted SCTP packet, trigger memory corruption and cause the service to crash.
Affected software
Linux kernel
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Fedora
MRG Realtime
kernel-rt (Red Hat package)
openSUSE Leap
kernel-alt (Red Hat package)
kernel
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Fedora
MRG Realtime
kernel-rt (Red Hat package)
openSUSE Leap
kernel-alt (Red Hat package)
kernel
How to mitigate CVE-2018-5803
Install update from vendor's website.
kernel-rt (Red Hat package) - update to 3.10.0-693.46.1.rt56.639.el6rt
kernel-alt (Red Hat package) - update to 4.14.0-115.el7a
kernel - update to 4.15.8-300.fc27
kernel-alt (Red Hat package) - update to 4.14.0-115.el7a
kernel - update to 4.15.8-300.fc27