Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Dr Silvio Cesare

Pesquisador deInfoSect
#33097de 53,635
7.8CVSS total
Vulnerabilidades · 1
PT-2018-18644
7.8
2018-03-20
Linux · Linux Kernel · CVE-2018-8822
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions through 4.15.11 Linux kernel versions 4.16-rc through 4.16-rc6 **Description** The issue is related to incorrect buffer length handling in the ncp read kernel function, which could be exploited by malicious NCPFS servers to crash the kernel or execute code. **Recommendations** For Linux kernel versions through 4.15.11, update to a version later than 4.15.11 to resolve the issue. For Linux kernel versions 4.16-rc through 4.16-rc6, update to a version later than 4.16-rc6 to resolve the issue. As a temporary workaround, consider restricting access to the ncp read kernel function in fs/ncpfs/ncplib kernel.c and drivers/staging/ncpfs/ncplib kernel.c to minimize the risk of exploitation.