PT-2018-18102 · Linux+3 · Linux Kernel+3

Andrey Konovalov

·

Published

2017-12-17

·

Updated

2019-03-26

·

CVE-2018-7492

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.14.7
Description A NULL pointer dereference issue was discovered in the rds rdma map() function, allowing local attackers to cause a system panic and a denial-of-service. This issue is related to RDS GET MR and RDS GET MR FOR DEST.
Recommendations For Linux kernel versions prior to 4.14.7, update to version 4.14.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the rds rdma map() function to minimize the risk of exploitation.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2806
ALT-PU-2018-1991
CVE-2018-7492
DLA-1369-1
DSA-4187-1
OPENSUSE-SU-2018_1418-1
OPENSUSE-SU-2018_2119-1
SUSE-SU-2018:1366-1
SUSE-SU-2018:1761-1
SUSE-SU-2018:1762-1
SUSE-SU-2018:1816-1
SUSE-SU-2018:1855-1
SUSE-SU-2018:1855-2
SUSE-SU-2018:2092-1
SUSE-SU-2018:2332-1
SUSE-SU-2018:2366-1
SUSE-SU-2018:2637-1
USN-3619-1
USN-3619-2
USN-3674-1
USN-3674-2
USN-3677-1
USN-3677-2

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu