CVE-2018-5703: Critical severity Google Android vulnerability
Published Jan 16, 2018
·Updated
The tcpv6synrecvsock function in net/ipv6/tcpipv6.c in the Linux kernel through 4.14.11 allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via vectors involving TLS.
Affected Software
3 affected components
Google Android
Linux Linux Kernel>=4.13<4.14.86
Linux Linux Kernel>=4.15<4.15.8
Event History
Jan 16, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
via NVD·09:29 AM
DescriptionSeverityWeaknessAffected Software
Jul 2, 2018
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5703?
CVE-2018-5703 is classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2018-5703?
To fix CVE-2018-5703, upgrade the Linux kernel to a version later than 4.14.86 or later than 4.15.8.
3
What systems are affected by CVE-2018-5703?
CVE-2018-5703 affects Linux kernel versions up to 4.14.11 and certain Android versions.
4
What type of vulnerability is CVE-2018-5703?
CVE-2018-5703 is a denial of service vulnerability that can also lead to slab out-of-bounds write issues.
5
What impact does CVE-2018-5703 have on security?
The impact of CVE-2018-5703 can lead to system crashes or potentially allow attackers to gain unspecified access.