Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-9568

Опубликовано: 28 сент. 2017
Источник: redhat
CVSS3: 7

Описание

In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.

A possible memory corruption due to a type confusion was found in the Linux kernel in the sk_clone_lock() function in the net/core/sock.c. The possibility of local escalation of privileges cannot be fully ruled out for a local unprivileged attacker.

Меры по смягчению последствий

The currently known attack vector uses IPv6 for exploitation. If IPv6 is not needed on the host, disabling it mitigates this attack vector. Please see https://access.redhat.com/solutions/8709 for instructions on how to disable IPv6 in Red Hat Enterprise Linux.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelWill not fix
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2019:273612.09.2019
Red Hat Enterprise Linux 6.5 Advanced Update SupportkernelFixedRHSA-2019:405603.12.2019
Red Hat Enterprise Linux 6.6 Advanced Update SupportkernelFixedRHSA-2019:425517.12.2019
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2019:051413.03.2019
Red Hat Enterprise Linux 7kernelFixedRHSA-2019:051213.03.2019
Red Hat Enterprise Linux 7.2 Advanced Update SupportkernelFixedRHSA-2019:416410.12.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1655904kernel: Memory corruption due to incorrect socket cloning

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.

CVSS3: 7.8
nvd
почти 7 лет назад

In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.

CVSS3: 7.8
debian
почти 7 лет назад

In sk_clone_lock of sock.c, there is a possible memory corruption due ...

suse-cvrf
почти 7 лет назад

Security update for the Linux Kernel (Live Patch 38 for SLE 12)

suse-cvrf
почти 7 лет назад

Security update for the Linux Kernel (Live Patch 29 for SLE 12 SP1)

7 High

CVSS3