Описание
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
The do_get_mempolicy() function in mm/mempolicy.c in the Linux kernel allows local users to hit a use-after-free bug via crafted system calls and thus cause a denial of service (DoS) or possibly have unspecified other impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | kernel | Will not fix | ||
Red Hat Enterprise Linux 7 | kernel-alt | Not affected | ||
Red Hat Enterprise Linux 8 | kernel | Not affected | ||
Red Hat Enterprise Linux 6 | kernel | Fixed | RHSA-2018:2164 | 10.07.2018 |
Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel | Fixed | RHSA-2018:2791 | 25.09.2018 |
Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel | Fixed | RHSA-2018:2933 | 16.10.2018 |
Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel | Fixed | RHSA-2018:2924 | 16.10.2018 |
Red Hat Enterprise Linux 6.6 Telco Extended Update Support | kernel | Fixed | RHSA-2018:2924 | 16.10.2018 |
Red Hat Enterprise Linux 6.7 Extended Update Support | kernel | Fixed | RHSA-2018:2925 | 17.10.2018 |
Red Hat Enterprise Linux 7 | kernel-rt | Fixed | RHSA-2018:2395 | 14.08.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel be ...
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
Уязвимость функции do_get_mempolicy() ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.5 Medium
CVSS3