CVE-2018-14646

CVSS v3.0 5.5 (Medium)
55% Progress
CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 7
Advisories 3

The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could exploit this when a net namespace with a netnsid is assigned to cause a kernel panic and a denial of service.

Weaknesses
CWE-476
NULL Pointer Dereference
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2018-11-26 19:29:00
(5 years ago)
Updated Date
2019-10-09 23:35:05
(5 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 4.14 and prior versions cpe:2.3:o:linux:linux_kernel <= 4.14
  Linux Kernel 4.15 Rc1 cpe:2.3:o:linux:linux_kernel:4.15:rc1
  Linux Kernel 4.15 Rc2 cpe:2.3:o:linux:linux_kernel:4.15:rc2
  Linux Kernel 4.15 Rc3 cpe:2.3:o:linux:linux_kernel:4.15:rc3
  Linux Kernel 4.15 Rc4 cpe:2.3:o:linux:linux_kernel:4.15:rc4
  Linux Kernel 4.15 Rc5 cpe:2.3:o:linux:linux_kernel:4.15:rc5
  Linux Kernel 4.15 Rc6 cpe:2.3:o:linux:linux_kernel:4.15:rc6
  Linux Kernel 4.15 Rc7 cpe:2.3:o:linux:linux_kernel:4.15:rc7

Configuration #2

    CPE23 From Up To
  Redhat Enterprise Linux Desktop 7.0 cpe:2.3:o:redhat:enterprise_linux_desktop:7.0
  Redhat Enterprise Linux Server 7.0 cpe:2.3:o:redhat:enterprise_linux_server:7.0
  Redhat Enterprise Linux Server Aus 7.6 cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6
  Redhat Enterprise Linux Server Eus 7.5 cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5
  Redhat Enterprise Linux Server Eus 7.6 cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6
  Redhat Enterprise Linux Server Tus 7.6 cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6
  Redhat Enterprise Linux Workstation 7.0 cpe:2.3:o:redhat:enterprise_linux_workstation:7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...