PT-2018-2963 · Linux+2 · Linux Kernel+2

Luo Quan

·

Published

2018-09-06

·

Updated

2026-05-26

·

CVE-2018-17977

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel version 4.14.67
Description The issue is related to incorrect handling of certain interactions between XFRM Netlink messages, IPPROTO AH packets, and IPPROTO IP packets. This can be exploited to cause a denial of service, resulting in memory consumption and system hang. The exploitation requires root access to execute crafted applications.
Recommendations For Linux kernel version 4.14.67, consider applying a patch or updating to a newer version that addresses this issue, as no specific workaround is provided for this version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2282
BDU:2019-02786
CVE-2018-17977
ECHO-3646-91BE-32B5

Affected Products

Alt Linux
Debian
Linux Kernel