PT-2017-3589 · Linux+5 · Linux Kernel+5

Dan Aloni

·

Publicado

2017-02-01

·

Atualizado

2019-04-23

·

CVE-2018-1066

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.11
Description: The issue is related to a NULL pointer dereference in the setup ntlmv2 rsp() function, located in fs/cifs/cifsencrypt.c. This occurs when an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery. An attacker controlling a CIFS server can exploit this to cause a kernel panic on a client system that has the server mounted. The vulnerability allows a remote attacker to trigger a kernel panic on a vulnerable system when it connects to a controlled CIFS resource.
Recommendations: For Linux kernel versions prior to 4.11, update to version 4.11 or later to resolve the issue. As a temporary workaround, consider restricting access to CIFS servers to minimize the risk of exploitation. Avoid using the setup ntlmv2 rsp() function until a patch is available.

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1617
ALT-PU-2018-1991
BDU:2018-00526
CESA-2018_1062
CVE-2018-1066
DLA-1422-1
DLA-1422-2
DSA-4187-1
DSA-4188-1
RHSA-2018:1062
RHSA-2018_1062
SUSE-SU-2018:0834-1
SUSE-SU-2018:0848-1
USN-3880-1
USN-3880-2

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu