cbcvebase.
CVE-2018-5803
published 2018-06-12

CVE-2018-5803: In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function…

PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.55%
42.7th percentile
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.15.11-1 (bookworm)linux 4.15.11-1 (bookworm)
linuxlinux_kernel< 3.2.1023.2.102
linuxlinux_kernel>= 0 < 4.15.11-14.15.11-1
linuxlinux_kernel>= 0 < 4.15.11-14.15.11-1
linuxlinux_kernel>= 0 < 4.15.11-14.15.11-1
linuxlinux_kernel>= 0 < 4.15.11-14.15.11-1
linuxlinux_kernel>= 0 < 3.13.0-153.2033.13.0-153.203
linuxlinux_kernel>= 0 < 4.4.0-127.1534.4.0-127.153
linuxlinux_kernel>= 3.3 < 4.1.514.1.51
linuxlinux_kernel>= 4.10 < 4.14.254.14.25
linuxlinux_kernel>= 4.15 < 4.15.84.15.8
linuxlinux_kernel>= 4.3 < 4.9.874.9.87
linux_foundationlinux_kernel
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatvirtualization_host

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.