Memory corruption in Linux kernel - CVE-2018-5803

 

Memory corruption in Linux kernel - CVE-2018-5803

Published: March 2, 2018 / Updated: March 21, 2018


Vulnerability identifier: #VU10812
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5803
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists in the _sctp_make_chunk() function due to boundary error. A local attacker can submit a crafted SCTP packet, trigger memory corruption and cause the service to crash.


Affected software

Linux kernel
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Fedora

MRG Realtime
kernel-rt (Red Hat package)
openSUSE Leap
kernel-alt (Red Hat package)
kernel

How to mitigate CVE-2018-5803

Install update from vendor's website.

kernel-rt (Red Hat package) - update to 3.10.0-693.46.1.rt56.639.el6rt
kernel-alt (Red Hat package) - update to 4.14.0-115.el7a
kernel - update to 4.15.8-300.fc27

External References

Related Security Bulletins