PT-2018-1069 · Linux+3 · Linux Kernel+3
Mohamed Ghannam
·
Publicado
2018-01-03
·
Atualizado
2024-06-15
·
CVE-2018-5332
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.2
Description
The issue is related to the rds message alloc sgs() function in the Linux kernel, which does not properly validate a value used during DMA page allocation. This can lead to a heap-based out-of-bounds write, potentially allowing an attacker to write beyond the boundaries of a buffer in memory. The vulnerability is associated with the rds rdma extra size function in net/rds/rdma.c.
Recommendations
For Linux kernel versions prior to 3.2, consider applying a patch or updating to a newer version to fix the issue with the rds message alloc sgs() function. As a temporary workaround, consider restricting the use of DMA page allocation to minimize the risk of exploitation.
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel
Suse
Ubuntu