CVE-2018-10938
published 2018-08-27CVE-2018-10938: A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel…
PriorityP433medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
5.00%
91.4th percentile
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.13.4-1 (bookworm) | linux 4.13.4-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.13.4-1 | 4.13.4-1 |
| linux | linux_kernel | >= 0 < 4.13.4-1 | 4.13.4-1 |
| linux | linux_kernel | >= 0 < 4.13.4-1 | 4.13.4-1 |
| linux | linux_kernel | >= 0 < 4.13.4-1 | 4.13.4-1 |
| linux | linux_kernel | >= 0 < 4.4.0-138.164 | 4.4.0-138.164 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c4j8-6xxf-p927: A flaw was found in the Linux kernel present since v4
ghsa_unreviewed·2022-05-13
CVE-2018-10938 [HIGH] CWE-835 GHSA-c4j8-6xxf-p927: A flaw was found in the Linux kernel present since v4
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-10-23·CVSS 5.9
CVE-2018-14734 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that an integer overflow existed in the CD-ROM driver of
the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-16658)
It was discovered that an integer overflow existed in the HID Bluetooth
implementation in the Linux kernel that could lead to a buffer overwrite.
An attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2018-9363)
Yves Younan discovered that the CIPSO labeling im
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-10-23·CVSS 5.9
CVE-2018-14734 [MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3797-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that an integer overflow existed in the CD-ROM driver of
the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-16658)
It was discovered that a integer overflow existed in the HID Bluetooth
implementation in the Linux kernel that could lead to a buffer ove
OSV
CVE-2018-10938: A flaw was found in the Linux kernel present since v4
osv·2018-08-27·CVSS 5.9
CVE-2018-10938 [MEDIUM] CVE-2018-10938: A flaw was found in the Linux kernel present since v4
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-23·CVSS 5.9
CVE-2018-10938 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that an integer overflow existed in the CD-ROM driver of
the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-16658)
It was discovered that an integer overflow existed in the HID Bluetooth
implementation in the Linux kernel that could lead to a buffer overwrite.
An attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2018-9363)
Yves Younan discovered
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-10-23·CVSS 5.9
CVE-2018-10938 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3797-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that an integer overflow existed in the CD-ROM driver of
the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-16658)
It was discovered that a integer overflow existed in the HID Bluet
Red Hat
kernel: infinite loop in net/ipv4/cipso_ipv4.c:cipso_v4_optptr() allows for DoS
vendor_redhat·2018-08-27·CVSS 5.9
CVE-2018-10938 [MEDIUM] CWE-400 kernel: infinite loop in net/ipv4/cipso_ipv4.c:cipso_v4_optptr() allows for DoS
kernel: infinite loop in net/ipv4/cipso_ipv4.c:cipso_v4_optptr() allows for DoS
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-
Debian
CVE-2018-10938: linux - A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc...
vendor_debian·2018·CVSS 5.9
CVE-2018-10938 [MEDIUM] CVE-2018-10938: linux - A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc...
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a denial-of-service. A certain non-default configuration of LSM (Linux Security Module) and NetLabel should be set up on a system before an attacker could leverage this flaw.
Scope: local
bookworm: resolved (fixed in 4.13.4-1)
bullseye: resolved (fixed in 4.13.4-1)
forky: resolved (fixed in 4.13.4-1)
sid: resolved (fixed in 4.13.4-1)
trixie: resolved (fixed in 4.13.4-1)
No detection rules found.
No public exploits indexed.
http://seclists.org/oss-sec/2018/q3/179http://www.securityfocus.com/bid/105154http://www.securitytracker.com/id/1041569https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10938https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=40413955ee265a5e42f710940ec78f5450d49149https://lists.debian.org/debian-lts-announce/2018/10/msg00003.htmlhttps://usn.ubuntu.com/3797-1/https://usn.ubuntu.com/3797-2/https://www.debian.org/security/2018/dsa-4308http://seclists.org/oss-sec/2018/q3/179http://www.securityfocus.com/bid/105154http://www.securitytracker.com/id/1041569https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10938https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=40413955ee265a5e42f710940ec78f5450d49149https://lists.debian.org/debian-lts-announce/2018/10/msg00003.htmlhttps://usn.ubuntu.com/3797-1/https://usn.ubuntu.com/3797-2/https://www.debian.org/security/2018/dsa-4308
2018-08-27
Published