PT-2018-18644 · Linux+3 · Linux Kernel+3
Dr Silvio Cesare
·
Published
2018-03-20
·
Updated
2024-06-15
·
CVE-2018-8822
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 4.15.11
Linux kernel versions 4.16-rc through 4.16-rc6
Description
The issue is related to incorrect buffer length handling in the ncp read kernel function, which could be exploited by malicious NCPFS servers to crash the kernel or execute code.
Recommendations
For Linux kernel versions through 4.15.11, update to a version later than 4.15.11 to resolve the issue.
For Linux kernel versions 4.16-rc through 4.16-rc6, update to a version later than 4.16-rc6 to resolve the issue.
As a temporary workaround, consider restricting access to the ncp read kernel function in fs/ncpfs/ncplib kernel.c and drivers/staging/ncpfs/ncplib kernel.c to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Suse
Ubuntu