PT-2018-2218 · Linux+5 · Linux Kernel+5

Published

2017-08-25

·

Updated

2023-02-24

·

CVE-2018-10675

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.12.9
Description The issue is related to the do get mempolicy() function in the Linux kernel, which is vulnerable to a use-after-free condition. This can be exploited by local users through specially crafted system calls, potentially leading to a denial of service or other unspecified impacts.
Recommendations For Linux kernel versions prior to 4.12.9, update to version 4.12.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the do get mempolicy() function until a patch is available.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2111
ALT-PU-2017-2114
BDU:2019-00255
CESA-2018_2164
CESA-2018_2384
CVE-2018-10675
RHSA-2018:2164
RHSA-2018:2384
RHSA-2018:2395
RHSA-2018:2785
RHSA-2018:2791
RHSA-2018:2924
RHSA-2018:2925
RHSA-2018:2933
RHSA-2018:3540
RHSA-2018:3586
RHSA-2018:3590
RHSA-2018_2164
RHSA-2018_2384
RHSA-2018_2395
SUSE-SU-2018:1368-1
SUSE-SU-2018:1374-1
SUSE-SU-2018:1375-1
SUSE-SU-2018:1376-1
SUSE-SU-2018:1846-1
USN-3754-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu