PT-2018-12635 · Linux · Linux Kernel

Vladis Dronov

·

Published

2018-09-18

·

Updated

2019-10-09

·

CVE-2018-14641

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 4.19-rc1 through 4.19-rc3
Description A security flaw was found in the ip frag reasm() function, which can cause a later system crash in ip do fragment(). With certain non-default configuration of a victim host, an attacker can trigger this crash remotely, leading to a remote denial-of-service.
Recommendations For Linux kernel versions 4.19-rc1 through 4.19-rc3, consider disabling the ip frag reasm() function as a temporary workaround until a patch is available. Restrict access to the affected ip do fragment() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14641
MGASA-2018-0391
MGASA-2018-0418
MGASA-2018-0419
RHSA-2018:2948

Affected Products

Linux Kernel