Denial of service in Linux kernel - CVE-2018-10021

 

Denial of service in Linux kernel - CVE-2018-10021

Published: April 16, 2018 / Updated: April 16, 2018


Vulnerability identifier: #VU11837
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10021
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists due to improper handling of analog telephone adapter (ATA) device commands by the drivers/scsi/libsas/sas_scsi_host.c source code file. A local attacker can execute ATA device commands to trigger certain failure conditions, trigger an ata qc leak and cause the service to crash.


Affected software

Linux kernel
Fedora
kernel

How to mitigate CVE-2018-10021

Update to version 4.16.

kernel - addressed in versions 4.15.17-200.fc26, 4.15.17-300.fc27

External References

Related Security Bulletins