#VU14736 Memory leak in Linux kernel - CVE-2018-6554
Published: September 10, 2018 / Updated: September 16, 2018
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the irda_bind() function in net/irda/af_irda.c and drivers/staging/irda/net/af_irda.c files in the Linux kernel before 4.17. A local user can cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket.