CVE-2018-17156: Medium severity freebsd kernel vulnerability
Published Nov 28, 2018
·Updated
In FreeBSD before 11.2-STABLE(r340268) and 11.2-RELEASE-p5, due to incorrectly accounting for padding on 64-bit platforms, a buffer underwrite could occur when constructing an ICMP reply packet when using a non-standard value for the net.inet.icmp.quotelen sysctl.
Affected Software
2 affected components
FreeBSD FreeBSD<11.2
FreeBSD FreeBSD=11.2-p5
Event History
Nov 28, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-17156?
CVE-2018-17156 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-17156?
To fix CVE-2018-17156, update FreeBSD to version 11.2-STABLE(r340268) or 11.2-RELEASE-p5 or later.
3
What types of systems are affected by CVE-2018-17156?
CVE-2018-17156 affects FreeBSD systems, specifically versions prior to 11.2-STABLE(r340268) and 11.2-RELEASE-p5.
4
What kind of attack does CVE-2018-17156 facilitate?
CVE-2018-17156 could facilitate a buffered underwrite attack when constructing ICMP reply packets.
5
Is CVE-2018-17156 exploitable remotely?
Yes, CVE-2018-17156 may be exploitable remotely through ICMP packets.