Severity
7.0HIGH
EPSS
7.3%
top 8.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 13

Description

A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depending on how the target's code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:HExploitability: 2.2 | Impact: 4.7

Affected Packages5 packages

CVEListV5the_linux_foundation/kernel4.18.x, 4.14.x, 3.10.x
NVDlinux/linux_kernel3.13.16.59+5
Debianlinux< 4.18.10-1+3

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, Enterprise Linux 7.4, 7.6

Patches

🔴Vulnerability Details

4
GHSA
GHSA-88p5-45fx-5x87: A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request fr2022-05-13
OSV
CVE-2018-14633: A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request fr2018-09-25
CVEList
CVE-2018-14633: A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request fr2018-09-25
Kernel
scsi: target: iscsi: Use hex2bin instead of a re-implementation2018-09-09

📋Vendor Advisories

10
Ubuntu
Linux kernel (Azure) vulnerabilities2018-10-23
Ubuntu
Linux kernel vulnerabilities2018-10-02
Ubuntu
Linux kernel (HWE) vulnerabilities2018-10-01
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2018-10-01
Ubuntu
Linux kernel vulnerabilities2018-10-01

💬Community

2
Bugzilla
CVE-2018-14633 kernel: stack-based buffer overflow in chap_server_compute_md5() in iscsi target [fedora-all]2018-09-24
Bugzilla
CVE-2018-14633 kernel: stack-based buffer overflow in chap_server_compute_md5() in iscsi target2018-09-06
CVE-2018-14633 (HIGH CVSS 7) | A security flaw was found in the ch | cvebase.io