Denial of service in Red Hat Enterprise Linux for x86_64 - CVE-2018-10872

 

Denial of service in Red Hat Enterprise Linux for x86_64 - CVE-2018-10872

Published: July 16, 2018 / Updated: July 16, 2018


Vulnerability identifier: #VU13877
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10872
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to a flaw in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, processor does not deliver interrupts and exceptions, they are delivered once the first instruction after the stack switch is executed. A remote attacker can crash the system kernel resulting in DoS.


Affected software

Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing

kernel (Red Hat package)

How to mitigate CVE-2018-10872

Install update from vendor's website.

kernel (Red Hat package) - update to 2.6.32-754.2.1.el6

External References

Related Security Bulletins