Type confusion in Linux kernel - CVE-2018-18386

 

Type confusion in Linux kernel - CVE-2018-18386

Published: October 19, 2018 / Updated: October 22, 2018


Vulnerability identifier: #VU15458
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-18386
CWE-ID: CWE-843
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists due to a type confusion condition in the drivers/tty/n_tty.csource code file. A local attacker can deny use of any other pseudoterminal devices on a targeted system when the EXTPROC and ICANON flags become confused in the TIOCINQ command.


Affected software

Linux kernel
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Opensuse

kernel-alt (Red Hat package)

How to mitigate CVE-2018-18386

Update to version 4.14.11.

Linux kernel - update to 4.14.11
kernel-alt (Red Hat package) - update to 4.14.0-115.7.1.el7a

External References

Related Security Bulletins