CVE-2018-18386: Incorrect Type Cast
drivers/tty/ntty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
linux kernelto a version that resolves this vulnerability.Fixed in 4.14.11
Event History
Frequently Asked Questions
What is CVE-2018-18386?
CVE-2018-18386 is a vulnerability in the Linux kernel that allows local attackers to hang/block further usage of pseudo terminal devices.
How severe is CVE-2018-18386?
CVE-2018-18386 has a severity level of medium.
Which Linux kernel versions are affected?
Linux kernel versions before 4.14.11 are affected by CVE-2018-18386.
How can I fix CVE-2018-18386?
To fix CVE-2018-18386, update your Linux kernel to version 4.14.11 or later.
Where can I find more information about CVE-2018-18386?
You can find more information about CVE-2018-18386 at the following references: - [Linux kernel commit](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=966031f340185eddd05affcf72b740549f056348) - [SUSE bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=1094825) - [Linux kernel ChangeLog](https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.11)