imPC@ndo IT

Tracker / CVE-2018-5803

CVE-2018-5803

Medium 5.5

In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.

Affected products and versions

debian debian_linux
linux linux_kernel · … → 3.2.102
linux linux_kernel · 3.3 → 4.1.51
linux linux_kernel · 4.10 → 4.14.25
linux linux_kernel · 4.15 → 4.15.8
linux linux_kernel · 4.3 → 4.9.87
redhat enterprise_linux_desktop
redhat enterprise_linux_server
redhat enterprise_linux_workstation
redhat virtualization_host

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References