CVE-2018-5803

CVSS v3.0 5.5 (Medium)
55% Progress
CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 6
Advisories 50

In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Flexera Software LLC
Published Date
2018-06-12 16:29:00
(6 years ago)
Updated Date
2019-03-27 16:17:25
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 3.2.102 version cpe:2.3:o:linux:linux_kernel < 3.2.102
  Linux Kernel from 3.3 version and prior 4.1.51 version cpe:2.3:o:linux:linux_kernel >= 3.3 < 4.1.51
  Linux Kernel from 4.3 version and prior 4.9.87 version cpe:2.3:o:linux:linux_kernel >= 4.3 < 4.9.87
  Linux Kernel from 4.10 version and prior 4.14.25 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.25
  Linux Kernel from 4.15 version and prior 4.15.8 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.15.8

Configuration #2

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0

Configuration #3

    CPE23 From Up To
  Redhat Virtualization Host 4.0 cpe:2.3:a:redhat:virtualization_host:4.0
  Redhat Enterprise Linux Desktop 7.0 cpe:2.3:o:redhat:enterprise_linux_desktop:7.0
  Redhat Enterprise Linux Server 7.0 cpe:2.3:o:redhat:enterprise_linux_server:7.0
  Redhat Enterprise Linux Workstation 7.0 cpe:2.3:o:redhat:enterprise_linux_workstation:7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...