PT-2018-1069 · Linux+3 · Linux Kernel+3

Mohamed Ghannam

·

Published

2018-01-03

·

Updated

2024-06-15

·

CVE-2018-5332

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.2
Description The issue is related to the rds message alloc sgs() function in the Linux kernel, which does not properly validate a value used during DMA page allocation. This can lead to a heap-based out-of-bounds write, potentially allowing an attacker to write beyond the boundaries of a buffer in memory. The vulnerability is associated with the rds rdma extra size function in net/rds/rdma.c.
Recommendations For Linux kernel versions prior to 3.2, consider applying a patch or updating to a newer version to fix the issue with the rds message alloc sgs() function. As a temporary workaround, consider restricting the use of DMA page allocation to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1046
ALT-PU-2018-1557
BDU:2018-00412
CVE-2018-5332
DLA-1369-1
DSA-4187-1
OPENSUSE-SU-2018_0408-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2018:0470
SUSE-SU-2018:0383-1
SUSE-SU-2018:0416-1
SUSE-SU-2018:0482-1
SUSE-SU-2018:0555-1
SUSE-SU-2018:0660-1
SUSE-SU-2018:0834-1
SUSE-SU-2018:0841-1
SUSE-SU-2018:0848-1
SUSE-SU-2018:0986-1
USN-3617-1
USN-3617-2
USN-3617-3
USN-3619-1
USN-3619-2
USN-3620-1
USN-3620-2
USN-3632-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu