PT-2018-2559 · Linux+5 · Linux Kernel+5

Andy Lutomirski

+1

·

Published

2018-06-04

·

Updated

2019-09-10

·

CVE-2018-14734

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 4.17.11
Description The issue is related to a use-after-free error in the ucma leave multicast function, allowing attackers to cause a denial of service. This occurs because the function accesses a certain data structure after a cleanup step in ucma process join. The exploitation of this issue may lead to a service disruption.
Recommendations For Linux kernel versions through 4.17.11, update to a version later than 4.17.11 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific issue.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2092
ALT-PU-2018-2094
ALT-PU-2019-1433
BDU:2019-00978
CESA-2019_2029
CVE-2018-14734
DLA-1529-1
DLA-1531-1
DSA-4308-1
OPENSUSE-SU-2018_2404-1
RHSA-2019:0831
RHSA-2019:2029
RHSA-2019:2043
RHSA-2019_2029
RHSA-2019_2043
SUSE-SU-2018:2328-1
SUSE-SU-2018:2344-1
SUSE-SU-2018:2344-2
SUSE-SU-2018:2362-1
SUSE-SU-2018:2374-1
SUSE-SU-2018:2384-1
SUSE-SU-2018:2596-1
SUSE-SU-2018:2879-1
SUSE-SU-2018:2907-1
SUSE-SU-2018:3088-1
SUSE-SU-2019:1422-1
SUSE-SU-2019:1437-1
SUSE-SU-2019:1489-1
SUSE-SU-2019_1422-1
SUSE-SU-2019_1437-1
SUSE-SU-2019_1489-1
USN-3797-1
USN-3797-2
USN-3847-1
USN-3847-2
USN-3847-3
USN-3849-1
USN-3849-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu