Out-of-bounds write in Linux kernel - CVE-2018-5703

 

Out-of-bounds write in Linux kernel - CVE-2018-5703

Published: June 12, 2018


Vulnerability identifier: #VU13259
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5703
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.

The weakness exists in the tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c due to slab out-of-bounds write. A remote attacker can supply vectors involving TLS, trigger memory corruption and cause the system to crash or execute arbitrary code with elevated privileges.

Affected software

Linux kernel
Fedora
kernel

How to mitigate CVE-2018-5703

Update to version 4.14.12.

kernel - update to 4.15.8-300.fc27

External References

Related Security Bulletins