PT-2018-2804 · Linux+1 · Linux Kernel+1
Vladis Dronov
·
Published
2018-08-21
·
Updated
2023-02-13
·
CVE-2018-14656
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is caused by a missing address check in the callers of the
show opcodes() function in the Linux kernel, allowing an attacker to dump kernel memory at an arbitrary kernel address into the dmesg log. This is also described as a vulnerability in the show opcodes() function due to input validation errors, which can be exploited to access protected kernel information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel