CVE-2018-18386
published 2018-10-17CVE-2018-18386: drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any…
PriorityP410low3.3CVSS 3.0
AVLACLPRLUINSUCNINAL
EPSS
0.41%
34.0th percentile
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.14.12-1 (bookworm) | linux 4.14.12-1 (bookworm) |
| linux | linux_kernel | < 4.14.11 | 4.14.11 |
| linux | linux_kernel | >= 0 < 4.14.12-1 | 4.14.12-1 |
| linux | linux_kernel | >= 0 < 4.14.12-1 | 4.14.12-1 |
| linux | linux_kernel | >= 0 < 4.14.12-1 | 4.14.12-1 |
| linux | linux_kernel | >= 0 < 4.14.12-1 | 4.14.12-1 |
| linux | linux_kernel | >= 0 < 3.13.0-164.214 | 3.13.0-164.214 |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j3hq-436j-w545: drivers/tty/n_tty
ghsa_unreviewed·2022-05-14
CVE-2018-18386 [LOW] CWE-704 GHSA-j3hq-436j-w545: drivers/tty/n_tty
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.
OSV
linux vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux ke
OSV
CVE-2018-18386: drivers/tty/n_tty
osv·2018-10-17·CVSS 3.3
CVE-2018-18386 [LOW] CVE-2018-18386: drivers/tty/n_tty
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-a
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3849-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was di
Debian
CVE-2018-18386: linux - drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (w...
vendor_debian·2018·CVSS 3.3
CVE-2018-18386 [LOW] CVE-2018-18386: linux - drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (w...
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.
Scope: local
bookworm: resolved (fixed in 4.14.12-1)
bullseye: resolved (fixed in 4.14.12-1)
forky: resolved (fixed in 4.14.12-1)
sid: resolved (fixed in 4.14.12-1)
trixie: resolved (fixed in 4.14.12-1)
Red Hat
kernel: Type confusion in drivers/tty/n_tty.c allows for a denial of service
vendor_redhat·2017-12-20·CVSS 3.3
CVE-2018-18386 [LOW] CWE-843 kernel: Type confusion in drivers/tty/n_tty.c allows for a denial of service
kernel: Type confusion in drivers/tty/n_tty.c allows for a denial of service
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.
A security flaw was found in the Linux kernel in drivers/tty/n_tty.c which allows local attackers (ones who are able to access pseudo terminals) to lock them up and block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ handler.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Ha
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=966031f340185eddd05affcf72b740549f056348https://access.redhat.com/errata/RHSA-2019:0831https://bugzilla.suse.com/show_bug.cgi?id=1094825https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.11https://github.com/torvalds/linux/commit/966031f340185eddd05affcf72b740549f056348https://usn.ubuntu.com/3849-1/https://usn.ubuntu.com/3849-2/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=966031f340185eddd05affcf72b740549f056348https://access.redhat.com/errata/RHSA-2019:0831https://bugzilla.suse.com/show_bug.cgi?id=1094825https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.11https://github.com/torvalds/linux/commit/966031f340185eddd05affcf72b740549f056348https://usn.ubuntu.com/3849-1/https://usn.ubuntu.com/3849-2/
2018-10-17
Published