Linux Kernel 'net/rds/rdma. c' Local Denial of Service Vulnerability (CVE-2018-5332)
Linux Kernel 'net/rds/rdma. c' Local Denial of Service Vulnerability (CVE-2018-5332)
Release date:
Updated on:
Affected Systems:
Linux kernel <= 4.14.13
Description:
Bugtraq id: 102507
CVE (CAN) ID: CVE-2018-5332
Linux Kernel is the Kernel of the Linux operating system.
In Linux kernel <= 4.14.13, The rds_message_alloc_sgs () function does not verify the value in the DMA page allocation. After successful exploitation, heap overwrite may occur.
<* Source: Mohamed Ghannam
*>
Suggestion:
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1533890
Https://access.redhat.com/security/cve/CVE-2018-5332
Http://www.kernel.org/
Https://github.com/torvalds/linux/commit/c095508770aebf1b9218e77026e48345d719b17c
Https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit? Id = c095508770aebf1b9218e77026e48345d719b17c