CVE-2017-18218: Use After Free
In drivers/net/ethernet/hisilicon/hns/hnsenet.c in the Linux kernel before 4.13, local users can cause a denial of service (use-after-free and BUG) or possibly have unspecified other impact by leveraging differences in skb handling between hnsnicnetxmithw and hnsnicnetxmit.
Affected Software
Remediation
Event History
Frequently Asked Questions
Who can exploit this issue?
A local user with existing low-level privileges can exploit it. The supplied CVSS vector requires local access and privileges, and does not require user interaction.
What is the likely impact of successful exploitation?
Successful exploitation can cause a denial of service through a use-after-free condition and kernel BUG. Other impacts are possible but unspecified in the available information.
Which systems should be prioritized for remediation?
Prioritize Linux kernel deployments using versions before 4.13, particularly systems that expose local access to untrusted or less-trusted users. The affected code is in the HiSilicon HNS Ethernet driver.
What remediation is available?
A patch is available in Linux kernel commit 27463ad99f738ed93c7c8b3e2e5bc8c4853a2ff2. Apply the vendor-provided kernel update or ensure the equivalent fix is present in the deployed kernel.