PT-2018-18259 · Linux+5 · Linux Kernel+5

Jason Yan

·

Publicado

2018-03-08

·

Atualizado

2026-02-06

·

CVE-2018-7757

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.15.8
Description: The issue allows local users to cause a denial of service due to memory consumption. This can be achieved via many read accesses to files in the /sys/class/sas phy directory. For example, accessing the /sys/class/sas phy/phy-1:0:12/invalid dword count file can demonstrate this issue.
Recommendations: For Linux kernel versions prior to 4.15.8, update to version 4.15.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the /sys/class/sas phy directory to minimize the risk of exploitation.

Correção

DoS

Missing Release of Resource after Effective Lifetime

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1557
ALT-PU-2019-1433
CESA-2018_3083
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2018-7757
DLA-1369-1
DSA-4187-1
DSA-4188-1
OPENSUSE-SU-2018_3202-1
RHSA-2018:2948
RHSA-2018:3083
RHSA-2018:3096
RHSA-2018_3083
RHSA-2018_3096
SUSE-SU-2018:1080-1
SUSE-SU-2018:1172-1
SUSE-SU-2018:1220-1
SUSE-SU-2018:1221-1
SUSE-SU-2018:1309-1
SUSE-SU-2018:3003-1
SUSE-SU-2018:3004-1
SUSE-SU-2018:3084-1
SUSE-SU-2018:3659-1
SUSE-SU-2019:0095-1
USN-3654-1
USN-3654-2
USN-3656-1
USN-3697-1
USN-3697-2
USN-3698-1
USN-3698-2

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu