Type confusion in Linux kernel - CVE-2018-18386
Published: October 19, 2018 / Updated: October 22, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to a type confusion condition in the drivers/tty/n_tty.csource code file. A local attacker can deny use of any other pseudoterminal devices on a targeted system when the EXTPROC and ICANON flags become confused in the TIOCINQ command.
Affected software
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Opensuse
kernel-alt (Red Hat package)
How to mitigate CVE-2018-18386
kernel-alt (Red Hat package) - update to 4.14.0-115.7.1.el7a