PT-2018-1069 · Linux+3 · Linux Kernel+3

Mohamed Ghannam

·

Publicado

2018-01-03

·

Atualizado

2024-06-15

·

CVE-2018-5332

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.2
Description The issue is related to the rds message alloc sgs() function in the Linux kernel, which does not properly validate a value used during DMA page allocation. This can lead to a heap-based out-of-bounds write, potentially allowing an attacker to write beyond the boundaries of a buffer in memory. The vulnerability is associated with the rds rdma extra size function in net/rds/rdma.c.
Recommendations For Linux kernel versions prior to 3.2, consider applying a patch or updating to a newer version to fix the issue with the rds message alloc sgs() function. As a temporary workaround, consider restricting the use of DMA page allocation to minimize the risk of exploitation.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1046
ALT-PU-2018-1557
BDU:2018-00412
CVE-2018-5332
DLA-1369-1
DSA-4187-1
OPENSUSE-SU-2018_0408-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2018:0470
SUSE-SU-2018:0383-1
SUSE-SU-2018:0416-1
SUSE-SU-2018:0482-1
SUSE-SU-2018:0555-1
SUSE-SU-2018:0660-1
SUSE-SU-2018:0834-1
SUSE-SU-2018:0841-1
SUSE-SU-2018:0848-1
SUSE-SU-2018:0986-1
USN-3617-1
USN-3617-2
USN-3617-3
USN-3619-1
USN-3619-2
USN-3620-1
USN-3620-2
USN-3632-1

Produtos afetados

Alt Linux
Linux Kernel
Suse
Ubuntu