PT-2017-3771 · Linux+3 · Linux Kernel+3

Published

2017-11-28

·

Updated

2023-05-16

·

CVE-2018-18559

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.20
Description A use-after-free issue exists in the Linux kernel due to a race condition between fanout add from setsockopt and bind on an AF PACKET socket. This occurs because of an incomplete fix for a race condition, which mishandles a certain multithreaded case involving a packet do bind unregister action followed by a packet notifier register action. The issue allows an attacker to achieve Program Counter control. The vulnerability is related to errors in synchronization when using a shared resource, which can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 4.20, update to a version that includes the complete fix for the race condition to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2806
ALT-PU-2017-2807
BDU:2019-00974
CESA-2019_0163
CVE-2018-18559
RHSA-2019:0163
RHSA-2019:0188
RHSA-2019:1170
RHSA-2019:1190
RHSA-2019:3967
RHSA-2019:4159
RHSA-2019_0163
RHSA-2019_0188
RHSA-2020:0174

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat