CVE-2018-1066
published 2018-03-02CVE-2018-1066: The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker…
PriorityP433medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
3.50%
88.0th percentile
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.11.6-1 (bookworm) | linux 4.11.6-1 (bookworm) |
| linux | linux_kernel | <= 4.10.15 | — |
| linux | linux_kernel | >= 0 < 4.11.6-1 | 4.11.6-1 |
| linux | linux_kernel | >= 0 < 4.11.6-1 | 4.11.6-1 |
| linux | linux_kernel | >= 0 < 4.11.6-1 | 4.11.6-1 |
| linux | linux_kernel | >= 0 < 4.11.6-1 | 4.11.6-1 |
| linux | linux_kernel | >= 0 < 3.13.0-165.215 | 3.13.0-165.215 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2019-02-04·CVSS 6.5
CVE-2018-1066 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3880-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that the CIFS client implementation in the Linux kernel
did not properly handle setup negotiation during session recovery, leading
to a NULL pointer exception. An attacker could use this to create a
malicious CIFS server that caused a denial of service (client system
crash). (CVE-2018-1066)
Jann Horn discovered that the procfs file system implementation in the
Linux kernel did not properly restrict the ability to inspect the kernel
stack of an arb
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-02-04·CVSS 6.5
CVE-2018-1066 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the CIFS client implementation in the Linux kernel
did not properly handle setup negotiation during session recovery, leading
to a NULL pointer exception. An attacker could use this to create a
malicious CIFS server that caused a denial of service (client system
crash). (CVE-2018-1066)
Jann Horn discovered that the procfs file system implementation in the
Linux kernel did not properly restrict the ability to inspect the kernel
stack of an arbitrary task. A local attacker could use this to expose
sensitive information. (CVE-2018-17972)
Jann Horn discovered that the mremap() system call in the Linux kernel did
not properly flush the TLB when completing, potentially
Debian
CVE-2018-1066: linux - The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference...
vendor_debian·2018·CVSS 6.5
CVE-2018-1066 [MEDIUM] CVE-2018-1066: linux - The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference...
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
Scope: local
bookworm: resolved (fixed in 4.11.6-1)
bullseye: resolved (fixed in 4.11.6-1)
forky: resolved (fixed in 4.11.6-1)
sid: resolved (fixed in 4.11.6-1)
trixie: resolved (fixed in 4.11.6-1)
Red Hat
kernel: Null pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() when empty TargetInfo is returned in NTLMSSP setup negotiation response allowing to crash client's kernel
vendor_redhat·2014-10-20·CVSS 6.5
CVE-2018-1066 [MEDIUM] CWE-476 kernel: Null pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() when empty TargetInfo is returned in NTLMSSP setup negotiation response allowing to crash client's kernel
kernel: Null pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() when empty TargetInfo is returned in NTLMSSP setup negotiation response allowing to crash client's kernel
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
A flaw was found in the Linux kernel's client-side implementation of the cifs protocol. This flaw allows an attacker controlling the server to kernel panic a client which has the CIFS server mounted.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package:
GHSA
GHSA-32qx-3229-j5m2: The Linux kernel before version 4
ghsa_unreviewed·2022-05-14
CVE-2018-1066 [HIGH] CWE-476 GHSA-32qx-3229-j5m2: The Linux kernel before version 4
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
OSV
linux vulnerabilities
osv·2019-02-04·CVSS 6.5
CVE-2018-1066 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that the CIFS client implementation in the Linux kernel
did not properly handle setup negotiation during session recovery, leading
to a NULL pointer exception. An attacker could use this to create a
malicious CIFS server that caused a denial of service (client system
crash). (CVE-2018-1066)
Jann Horn discovered that the procfs file system implementation in the
Linux kernel did not properly restrict the ability to inspect the kernel
stack of an arbitrary task. A local attacker could use this to expose
sensitive information. (CVE-2018-17972)
Jann Horn discovered that the mremap() system call in the Linux kernel did
not properly flush the TLB when completing, potentially leaving access to a
physical page after it has been released to the page allocat
OSV
CVE-2018-1066: The Linux kernel before version 4
osv·2018-03-02·CVSS 6.5
CVE-2018-1066 [MEDIUM] CVE-2018-1066: The Linux kernel before version 4
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cabfb3680f78981d26c078a26e5c748531257ebbhttp://www.securityfocus.com/bid/103378https://bugzilla.redhat.com/show_bug.cgi?id=1539599https://github.com/torvalds/linux/commit/cabfb3680f78981d26c078a26e5c748531257ebbhttps://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlhttps://patchwork.kernel.org/patch/10187633/https://usn.ubuntu.com/3880-1/https://usn.ubuntu.com/3880-2/https://www.debian.org/security/2018/dsa-4187https://www.debian.org/security/2018/dsa-4188http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cabfb3680f78981d26c078a26e5c748531257ebbhttp://www.securityfocus.com/bid/103378https://bugzilla.redhat.com/show_bug.cgi?id=1539599https://github.com/torvalds/linux/commit/cabfb3680f78981d26c078a26e5c748531257ebbhttps://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlhttps://patchwork.kernel.org/patch/10187633/https://usn.ubuntu.com/3880-1/https://usn.ubuntu.com/3880-2/https://www.debian.org/security/2018/dsa-4187https://www.debian.org/security/2018/dsa-4188
2018-03-02
Published