PT-2018-2804 · Linux+1 · Linux Kernel+1

Vladis Dronov

·

Publicado

2018-08-21

·

Atualizado

2023-02-13

·

CVE-2018-14656

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is caused by a missing address check in the callers of the show opcodes() function in the Linux kernel, allowing an attacker to dump kernel memory at an arbitrary kernel address into the dmesg log. This is also described as a vulnerability in the show opcodes() function due to input validation errors, which can be exploited to access protected kernel information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2192
ALT-PU-2018-2210
ALT-PU-2019-1433
BDU:2019-02163
CVE-2018-14656

Produtos afetados

Alt Linux
Linux Kernel