CVE-2018-6555: Use After Free
Last updated 25 August 2025
Other sources
The irdasetsockopt function in net/irda/afirda.c and later in drivers/staging/irda/net/afirda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (iasobject use-after-free and system crash) or possibly have unspecified other impact via an AFIRDA socket.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 4.17
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-6555.
What is the severity of CVE-2018-6555?
The severity of CVE-2018-6555 is not specified.
What is the impact of CVE-2018-6555?
CVE-2018-6555 can cause a denial of service (DoS) or have other unspecified impacts.
How can local users exploit CVE-2018-6555?
Local users can exploit CVE-2018-6555 by using an AF_IRDA socket.
Is there a fix available for CVE-2018-6555?
Yes, the fix for CVE-2018-6555 is available in Linux kernel version 4.17 and later.