First published: Fri Mar 02 2018(Updated: )
An error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited by a malicious local user to cause a kernel crash and a DoS. References: <a href="https://packetstormsecurity.com/files/146620/secunia-sctpmakechunkdos.txt">https://packetstormsecurity.com/files/146620/secunia-sctpmakechunkdos.txt</a> <a href="https://marc.info/?t=151818093200004&r=1&w=2">https://marc.info/?t=151818093200004&r=1&w=2</a> <a href="https://marc.info/?t=151818682600001&r=1&w=2">https://marc.info/?t=151818682600001&r=1&w=2</a> An upstream patch: <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=07f2c7ab6f8d0a7e7c5764c4e6cc9c52951b9d9c">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=07f2c7ab6f8d0a7e7c5764c4e6cc9c52951b9d9c</a>
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <3.2.102 | |
Linux Kernel | >=3.3<4.1.51 | |
Linux Kernel | >=4.3<4.9.87 | |
Linux Kernel | >=4.10<4.14.25 | |
Linux Kernel | >=4.15<4.15.8 | |
Debian | =7.0 | |
Debian | =8.0 | |
Debian | =9.0 | |
Red Hat Virtualization Host EUS | =4.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5803 is classified as a high severity vulnerability due to its potential to cause a denial of service through kernel crashes.
To fix CVE-2018-5803, update your system to the latest patched version of the Linux kernel or affected software.
CVE-2018-5803 affects Linux Kernel versions prior to 3.2.102 and several versions between 3.3 and 4.15.
No, CVE-2018-5803 requires local access to exploit, as it affects handling of SCTP packets.
The potential impacts of CVE-2018-5803 include system instability and denial of service due to kernel crashes.