PT-2018-1069 · Linux+3 · Linux Kernel+3
Mohamed Ghannam
·
Published
2018-01-03
·
Updated
2024-06-15
·
CVE-2018-5332
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.2
Description
The issue is related to the rds message alloc sgs() function in the Linux kernel, which does not properly validate a value used during DMA page allocation. This can lead to a heap-based out-of-bounds write, potentially allowing an attacker to write beyond the boundaries of a buffer in memory. The vulnerability is associated with the rds rdma extra size function in net/rds/rdma.c.
Recommendations
For Linux kernel versions prior to 3.2, consider applying a patch or updating to a newer version to fix the issue with the rds message alloc sgs() function. As a temporary workaround, consider restricting the use of DMA page allocation to minimize the risk of exploitation.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Suse
Ubuntu