CVE-2018-5344Race Condition in Kernel

Severity
7.8HIGHNVD
EPSS
0.1%
top 80.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 13

Description

In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (__lock_acquire use-after-free) or possibly have unspecified other impact.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

Also affects: Ubuntu Linux 12.04, 14.04, 16.04, 17.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qvpq-6qhx-422f: In the Linux kernel through 42022-05-13
CVEList
CVE-2018-5344: In the Linux kernel through 42018-01-12
OSV
CVE-2018-5344: In the Linux kernel through 42018-01-12

📋Vendor Advisories

10
Ubuntu
Linux kernel (Azure) vulnerabilities2018-04-24
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2018-04-05
Ubuntu
Linux kernel vulnerabilities2018-04-04
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities2018-04-04
Ubuntu
Linux kernel vulnerabilities2018-04-03

💬Community

2
Bugzilla
CVE-2018-5344 kernel: drivers/block/loop.c mishandles lo_release serialization allowing denial-of-service2018-01-12
Bugzilla
CVE-2018-5344 kernel: drivers/block/loop.c mishandles lo_release serialization allowing denial-of-service [fedora-all]2018-01-12
CVE-2018-5344 — Race Condition in Linux Kernel | cvebase