CVE-2018-7740Improper Restriction of Operations within the Bounds of a Memory Buffer in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 74.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 14

Description

The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-cgrc-gg26-w6wg: The resv_map_release function in mm/hugetlb2022-05-14
CVEList
CVE-2018-7740: The resv_map_release function in mm/hugetlb2018-03-07
OSV
CVE-2018-7740: The resv_map_release function in mm/hugetlb2018-03-07

📋Vendor Advisories

4
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2019-03-15
Ubuntu
Linux kernel vulnerabilities2019-03-15
Red Hat
kernel: Denial of service in resv_map_release function in mm/hugetlb.c2018-03-07
Debian
CVE-2018-7740: linux - The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7...2018

💬Community

2
Bugzilla
CVE-2018-7740 kernel: Denial of service in resv_map_release function in mm/hugetlb.c2018-03-07
Bugzilla
CVE-2018-7740 kernel: Denial of service in resv_map_release function in mm/hugetlb.c [fedora-all]2018-03-07
CVE-2018-7740 — Linux Kernel vulnerability | cvebase