Privilege escalation in Linux kernel - CVE-2018-8822
Published: March 22, 2018
Vulnerability identifier: #VU11228
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8822
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the ncp_read_kernel function due to incorrect buffer length handling. A local attacker can submit specially crafted data from a malicious NCPFS server, trigger memory corruption and execute arbitrary code with root privileges.
The weakness exists in the ncp_read_kernel function due to incorrect buffer length handling. A local attacker can submit specially crafted data from a malicious NCPFS server, trigger memory corruption and execute arbitrary code with root privileges.
Affected software
Linux kernel
Debian Linux
SUSE Linux
openSUSE Leap
Debian Linux
SUSE Linux
openSUSE Leap
How to mitigate CVE-2018-8822
Install update from vendor's website.
External References
Related Security Bulletins
- Privilege escalation in Linux kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- Debian update for linux
- Debian update for linux
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for the Linux Kernel