Out-of-bounds write in Linux kernel - CVE-2018-5703
Published: June 12, 2018
Vulnerability identifier: #VU13259
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5703
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.
The weakness exists in the tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c due to slab out-of-bounds write. A remote attacker can supply vectors involving TLS, trigger memory corruption and cause the system to crash or execute arbitrary code with elevated privileges.
The weakness exists in the tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c due to slab out-of-bounds write. A remote attacker can supply vectors involving TLS, trigger memory corruption and cause the system to crash or execute arbitrary code with elevated privileges.
Affected software
Linux kernel
Fedora
kernel
Fedora
kernel
How to mitigate CVE-2018-5703
Update to version 4.14.12.
kernel - update to 4.15.8-300.fc27