Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Luo Quan

Researcher from360 ESG Codesafe Team
#49897of 53,633
4.9Total CVSS
Vulnerabilities · 1
PT-2018-2963
4.9
2018-09-06
Linux · Linux Kernel · CVE-2018-17977
**Name of the Vulnerable Software and Affected Versions** Linux kernel version 4.14.67 **Description** The issue is related to incorrect handling of certain interactions between XFRM Netlink messages, IPPROTO AH packets, and IPPROTO IP packets. This can be exploited to cause a denial of service, resulting in memory consumption and system hang. The exploitation requires root access to execute crafted applications. **Recommendations** For Linux kernel version 4.14.67, consider applying a patch or updating to a newer version that addresses this issue, as no specific workaround is provided for this version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.